CWE-377 · 98 records
Insecure Temporary File
CVEs in this class
98 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2015-5224No exploit | The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly okernel · util-linux · CWE-377 | Critical9.8 | — | 4.5% | Aug 23, 2017 |
40Plan | CVE-2012-2666No exploit | golang/go in 1.0.2 fixes all.bash on shared machines.golang · go · CWE-377 | Critical9.8 | — | 1.9% | Jul 9, 2021 |
40Plan | CVE-2011-4119No exploit | caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.inria · caml-light · CWE-377 | Critical9.8 | — | 1.9% | Oct 26, 2021 |
39Monitor | CVE-2018-25068No exploit | devent globalpom-utils FileResourceManagerProvider.java createTmpDir temp fileglobalpom-utils project · globalpom-utils · CWE-377 | Critical9.8 | — | 0.8% | Jan 6, 2023 |
37Monitor | CVE-2025-14307No exploit | Insecure Temporary File Creation in Robocode's AutoExtract Componentrobocode · robocode · CWE-377 | Critical9.3 | — | 0.3% | Dec 9, 2025 |
36Monitor | CVE-2018-16494No exploit | In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissiversa-networks · versa operating system · CWE-377 | High8.8 | — | 1.9% | May 26, 2021 |
36Monitor | CVE-2013-4561No exploit | In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file.redhat · openshift · CWE-377 | Critical9.1 | — | 1.4% | Jun 30, 2022 |
33Monitor | CVE-2022-21809No exploit | A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4.inhandnetworks · inrouter302 firmware · CWE-377 | High8.1 | — | 1.8% | May 12, 2022 |
32Monitor | CVE-2018-3710No exploit | Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resultingitlab · gitlab · CWE-377 | High7.8 | — | 2.8% | Mar 21, 2018 |
32Monitor | CVE-2023-43498No exploit | In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the jenkins · jenkins · CWE-377 | High8.1 | — | 1.0% | Sep 20, 2023 |
31Monitor | CVE-2022-4817No exploit | centic9 jgit-cookbook temp filejgit-cookbook project · jgit-cookbook · CWE-377 | High7.8 | — | 0.5% | Dec 28, 2022 |
31Monitor | CVE-2018-6705No exploit | McAfee Agent (MA) for Linux Privilege Escalation vulnerabilitymcafee · agent · CWE-377 | High7.8 | — | 0.4% | Dec 12, 2018 |
31Monitor | CVE-2018-6704No exploit | McAfee Agent for Linux Privilege Escalation vulnerabilitymcafee · agent · CWE-377 | High7.8 | — | 0.4% | Dec 12, 2018 |
31Monitor | CVE-2020-1981No exploit | PAN-OS: Predictable temporary filename vulnerability allows local privilege escalationpaloaltonetworks · pan-os · CWE-377 | High7.8 | — | 0.4% | Mar 11, 2020 |
31Monitor | CVE-2023-49342No exploit | Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | High7.8 | — | 0.3% | Dec 14, 2023 |
31Monitor | CVE-2023-49347No exploit | Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | High7.8 | — | 0.3% | Dec 14, 2023 |
31Monitor | CVE-2023-49346No exploit | Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | High7.8 | — | 0.3% | Dec 14, 2023 |
31Monitor | CVE-2023-49344No exploit | Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | High7.8 | — | 0.3% | Dec 14, 2023 |
31Monitor | CVE-2023-49345No exploit | Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated.ubuntubudgie · budgie extras · CWE-377 | High7.8 | — | 0.3% | Dec 14, 2023 |
31Monitor | CVE-2025-7707No exploit | World-Writable NLTK Cache Directory Vulnerability in run-llama/llama_indexllamaindex · llamaindex · CWE-377 | High7.8 | — | 0.2% | Oct 13, 2025 |
31Monitor | CVE-2022-34387No exploit | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privildell · supportassist for business pcs · CWE-377 | High7.8 | — | 0.2% | Feb 10, 2023 |
31Monitor | CVE-2025-46369No exploit | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability.dell · alienware command center · CWE-377 | High7.8 | — | 0.1% | Nov 13, 2025 |
30Monitor | CVE-2022-0736No exploit | Insecure Temporary File in mlflow/mlflowlfprojects · mlflow · CWE-377 | High7.5 | — | 1.6% | Feb 23, 2022 |
30Monitor | CVE-2022-0315No exploit | Insecure Temporary File in horovod/horovodhorovod · horovod · CWE-377 | High7.5 | — | 1.0% | Mar 24, 2022 |
30Monitor | CVE-2013-4253No exploit | The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in redhat · openshift · CWE-377 | High7.5 | — | 0.6% | Oct 19, 2022 |
- CVE-2015-522440Plan
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly o
CriticalCVSS 9.8No exploitEPSS 5%kernel · util-linuxAug 23, 2017
- CVE-2012-266640Plan
golang/go in 1.0.2 fixes all.bash on shared machines.
CriticalCVSS 9.8No exploitEPSS 2%golang · goJul 9, 2021
- CVE-2011-411940Plan
caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.
CriticalCVSS 9.8No exploitEPSS 2%inria · caml-lightOct 26, 2021
- CVE-2018-2506839Monitor
devent globalpom-utils FileResourceManagerProvider.java createTmpDir temp file
CriticalCVSS 9.8No exploitEPSS 1%globalpom-utils project · globalpom-utilsJan 6, 2023
- CVE-2025-1430737Monitor
Insecure Temporary File Creation in Robocode's AutoExtract Component
CriticalCVSS 9.3No exploitEPSS 0%robocode · robocodeDec 9, 2025
- CVE-2018-1649436Monitor
In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissi
HighCVSS 8.8No exploitEPSS 2%versa-networks · versa operating systemMay 26, 2021
- CVE-2013-456136Monitor
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file.
CriticalCVSS 9.1No exploitEPSS 1%redhat · openshiftJun 30, 2022
- CVE-2022-2180933Monitor
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4.
HighCVSS 8.1No exploitEPSS 2%inhandnetworks · inrouter302 firmwareMay 12, 2022
- CVE-2018-371032Monitor
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resultin
HighCVSS 7.8No exploitEPSS 3%gitlab · gitlabMar 21, 2018
- CVE-2023-4349832Monitor
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the
HighCVSS 8.1No exploitEPSS 1%jenkins · jenkinsSep 20, 2023
- CVE-2022-481731Monitor
centic9 jgit-cookbook temp file
HighCVSS 7.8No exploitEPSS 1%jgit-cookbook project · jgit-cookbookDec 28, 2022
- CVE-2018-670531Monitor
McAfee Agent (MA) for Linux Privilege Escalation vulnerability
HighCVSS 7.8No exploitEPSS 0%mcafee · agentDec 12, 2018
- CVE-2018-670431Monitor
McAfee Agent for Linux Privilege Escalation vulnerability
HighCVSS 7.8No exploitEPSS 0%mcafee · agentDec 12, 2018
- CVE-2020-198131Monitor
PAN-OS: Predictable temporary filename vulnerability allows local privilege escalation
HighCVSS 7.8No exploitEPSS 0%paloaltonetworks · pan-osMar 11, 2020
- CVE-2023-4934231Monitor
Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated.
HighCVSS 7.8No exploitEPSS 0%ubuntubudgie · budgie extrasDec 14, 2023
- CVE-2023-4934731Monitor
Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated.
HighCVSS 7.8No exploitEPSS 0%ubuntubudgie · budgie extrasDec 14, 2023
- CVE-2023-4934631Monitor
Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated.
HighCVSS 7.8No exploitEPSS 0%ubuntubudgie · budgie extrasDec 14, 2023
- CVE-2023-4934431Monitor
Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated.
HighCVSS 7.8No exploitEPSS 0%ubuntubudgie · budgie extrasDec 14, 2023
- CVE-2023-4934531Monitor
Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated.
HighCVSS 7.8No exploitEPSS 0%ubuntubudgie · budgie extrasDec 14, 2023
- CVE-2025-770731Monitor
World-Writable NLTK Cache Directory Vulnerability in run-llama/llama_index
HighCVSS 7.8No exploitEPSS 0%llamaindex · llamaindexOct 13, 2025
- CVE-2022-3438731Monitor
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privil
HighCVSS 7.8No exploitEPSS 0%dell · supportassist for business pcsFeb 10, 2023
- CVE-2025-4636931Monitor
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability.
HighCVSS 7.8No exploitEPSS 0%dell · alienware command centerNov 13, 2025
- CVE-2022-073630Monitor
Insecure Temporary File in mlflow/mlflow
HighCVSS 7.5No exploitEPSS 2%lfprojects · mlflowFeb 23, 2022
- CVE-2022-031530Monitor
Insecure Temporary File in horovod/horovod
HighCVSS 7.5No exploitEPSS 1%horovod · horovodMar 24, 2022
- CVE-2013-425330Monitor
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in
HighCVSS 7.5No exploitEPSS 1%redhat · openshiftOct 19, 2022