CWE-379 · 52 записей
Creation of Temporary File in Directory with Insecure Permissions
CVE этого класса
52 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2024-9950Proof of concept | Abuse of Unauthenticated Compliance Recheck in SecureConnectorforescout · secureconnector · CWE-379 | Высокая8,5 | — | 0,3 % | 2 янв. 2025 г. |
32Наблюдать | CVE-2020-11979Эксплойта нет | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was alapache · ant · CWE-379 | Высокая7,5 | — | 8,0 % | 1 окт. 2020 г. |
32Наблюдать | CVE-2023-26396Эксплойта нет | Adobe Acrobat Reader DC for macOS installer (AcroRdrDC_2200220191_MUI.pkg) contains a local privilege escalation vulnerability.adobe · acrobat · CWE-379 | Высокая7,8 | — | 4,0 % | 12 апр. 2023 г. |
32Наблюдать | CVE-2021-21100Эксплойта нет | Adobe Digital Editions Arbitrary file system write vulnerabilityadobe · digital editions · CWE-379 | Высокая7,8 | — | 1,7 % | 15 апр. 2021 г. |
31Наблюдать | CVE-2022-23950Эксплойта нет | In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prkeylime · keylime · CWE-379 | Высокая7,5 | — | 1,7 % | 21 сент. 2022 г. |
31Наблюдать | CVE-2016-9486Эксплойта нет | On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privilforescout · secureconnector · CWE-379 | Высокая7,8 | — | 1,3 % | 13 июл. 2018 г. |
31Наблюдать | CVE-2023-21612Эксплойта нет | Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalationadobe · acrobat dc · CWE-379 | Высокая7,8 | — | 0,4 % | 18 янв. 2023 г. |
31Наблюдать | CVE-2023-21611Эксплойта нет | Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalationadobe · acrobat dc · CWE-379 | Высокая7,8 | — | 0,4 % | 18 янв. 2023 г. |
31Наблюдать | CVE-2023-49797Эксплойта нет | Local Privilege Escalation in pyinstaller on Windowspyinstaller · pyinstaller · CWE-379 | Высокая7,8 | — | 0,3 % | 8 дек. 2023 г. |
31Наблюдать | CVE-2023-3972Эксплойта нет | Insights-client: unsafe handling of temporary files and directoriesredhat · insights-client · CWE-379 | Высокая7,8 | — | 0,3 % | 1 нояб. 2023 г. |
31Наблюдать | CVE-2021-31411Эксплойта нет | Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19vaadin · flow · CWE-379 | Высокая7,8 | — | 0,2 % | 5 мая 2021 г. |
31Наблюдать | CVE-2023-6080Эксплойта нет | Privilege Escalation to SYSTEM in Lakeside Software Installerlakesidesoftware · systrack lsiagent · CWE-379 | Высокая7,8 | — | 0,2 % | 18 окт. 2024 г. |
31Наблюдать | CVE-2023-32450Эксплойта нет | Dell Power Manager, Versions 3.3 to 3.14 contains an Improper Access Control vulnerability.dell · power manager · CWE-379 | Высокая7,8 | — | 0,2 % | 27 июл. 2023 г. |
31Наблюдать | CVE-2024-9500Эксплойта нет | Autodesk ADP Desktop SDK Privilege Escalation Vulnerabilityautodesk · installer · CWE-379 | Высокая7,8 | — | 0,2 % | 15 нояб. 2024 г. |
31Наблюдать | CVE-2023-3181Эксплойта нет | Insecure Permissions in Splashtop Software Updatersplashtop · mirroring360 receiver · CWE-379 | Высокая7,8 | — | 0,2 % | 25 янв. 2024 г. |
31Наблюдать | CVE-2023-37243Эксплойта нет | The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system rebooatera · agent package availability · CWE-379 | Высокая7,8 | — | 0,2 % | 31 окт. 2023 г. |
31Наблюдать | CVE-2026-42191Эксплойта нет | OpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP Exporteropentelemetry · opentelemetry.exporter.opentelemetryprotocol · CWE-379 | Высокая7,8 | — | 0,1 % | 12 мая 2026 г. |
30Наблюдать | CVE-2021-40708Эксплойта нет | Adobe Genuine Service Installer Privilege Escalation Vulnerabilityadobe · genuine service · CWE-379 | Высокая7,3 | — | 1,7 % | 29 сент. 2021 г. |
30Наблюдать | CVE-2026-12555Эксплойта нет | HP Easy Start for macOS - Security Updatehp inc · hp easy start for macos · CWE-379 | Высокая7,7 | — | 0,4 % | 24 авг. 2026 г. |
29Наблюдать | CVE-2025-21173Эксплойта нет | .NET Elevation of Privilege Vulnerabilitymicrosoft · visual studio 2022 · CWE-379 | Высокая7,3 | — | 1,2 % | 14 янв. 2025 г. |
29Наблюдать | CVE-2021-36002Эксплойта нет | Adobe Captivate Installer Creation of Temporary File In Directory With Incorrect Permissions Could Lead To Privilege Escalationadobe · captivate · CWE-379 | Высокая7,3 | — | 0,5 % | 1 сент. 2021 г. |
29Наблюдать | CVE-2021-28613Эксплойта нет | Adobe Creative Cloud Arbitrary File Overwrite Vulnerabilityadobe · creative cloud desktop application · CWE-379 | Высокая7,4 | — | 0,5 % | 27 сент. 2021 г. |
29Наблюдать | CVE-2026-85028Эксплойта нет | Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kitaws · aws-fpga · CWE-379 | Высокая7,3 | — | 0,2 % | 3 сент. 2026 г. |
29Наблюдать | CVE-2026-54328Эксплойта нет | Pi: Predictable temporary extension install paths allow local privilege escalation on shared Linux hostsearendil-works · pi · CWE-379 | Высокая7,3 | — | 0,2 % | 23 июн. 2026 г. |
29Наблюдать | CVE-2024-7562Эксплойта нет | A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom arevenera · installshield · CWE-379 | Высокая7,3 | — | 0,1 % | 12 июн. 2025 г. |
- CVE-2024-995034Наблюдать
Abuse of Unauthenticated Compliance Recheck in SecureConnector
ВысокаяCVSS 8,5Proof of conceptEPSS 0 %forescout · secureconnector2 янв. 2025 г.
- CVE-2020-1197932Наблюдать
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was al
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %apache · ant1 окт. 2020 г.
- CVE-2023-2639632Наблюдать
Adobe Acrobat Reader DC for macOS installer (AcroRdrDC_2200220191_MUI.pkg) contains a local privilege escalation vulnerability.
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %adobe · acrobat12 апр. 2023 г.
- CVE-2021-2110032Наблюдать
Adobe Digital Editions Arbitrary file system write vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %adobe · digital editions15 апр. 2021 г.
- CVE-2022-2395031Наблюдать
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to pr
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %keylime · keylime21 сент. 2022 г.
- CVE-2016-948631Наблюдать
On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privil
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %forescout · secureconnector13 июл. 2018 г.
- CVE-2023-2161231Наблюдать
Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalation
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · acrobat dc18 янв. 2023 г.
- CVE-2023-2161131Наблюдать
Adobe Acrobat Reader Creation of Temporary File in Directory with Incorrect Permissions Privilege escalation
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · acrobat dc18 янв. 2023 г.
- CVE-2023-4979731Наблюдать
Local Privilege Escalation in pyinstaller on Windows
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %pyinstaller · pyinstaller8 дек. 2023 г.
- CVE-2023-397231Наблюдать
Insights-client: unsafe handling of temporary files and directories
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %redhat · insights-client1 нояб. 2023 г.
- CVE-2021-3141131Наблюдать
Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %vaadin · flow5 мая 2021 г.
- CVE-2023-608031Наблюдать
Privilege Escalation to SYSTEM in Lakeside Software Installer
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %lakesidesoftware · systrack lsiagent18 окт. 2024 г.
- CVE-2023-3245031Наблюдать
Dell Power Manager, Versions 3.3 to 3.14 contains an Improper Access Control vulnerability.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %dell · power manager27 июл. 2023 г.
- CVE-2024-950031Наблюдать
Autodesk ADP Desktop SDK Privilege Escalation Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %autodesk · installer15 нояб. 2024 г.
- CVE-2023-318131Наблюдать
Insecure Permissions in Splashtop Software Updater
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %splashtop · mirroring360 receiver25 янв. 2024 г.
- CVE-2023-3724331Наблюдать
The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboo
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %atera · agent package availability31 окт. 2023 г.
- CVE-2026-4219131Наблюдать
OpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP Exporter
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %opentelemetry · opentelemetry.exporter.opentelemetryprotocol12 мая 2026 г.
- CVE-2021-4070830Наблюдать
Adobe Genuine Service Installer Privilege Escalation Vulnerability
ВысокаяCVSS 7,3Эксплойта нетEPSS 2 %adobe · genuine service29 сент. 2021 г.
- CVE-2026-1255530Наблюдать
HP Easy Start for macOS - Security Update
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %hp inc · hp easy start for macos24 авг. 2026 г.
- CVE-2025-2117329Наблюдать
.NET Elevation of Privilege Vulnerability
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %microsoft · visual studio 202214 янв. 2025 г.
- CVE-2021-3600229Наблюдать
Adobe Captivate Installer Creation of Temporary File In Directory With Incorrect Permissions Could Lead To Privilege Escalation
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %adobe · captivate1 сент. 2021 г.
- CVE-2021-2861329Наблюдать
Adobe Creative Cloud Arbitrary File Overwrite Vulnerability
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %adobe · creative cloud desktop application27 сент. 2021 г.
- CVE-2026-8502829Наблюдать
Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %aws · aws-fpga3 сент. 2026 г.
- CVE-2026-5432829Наблюдать
Pi: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %earendil-works · pi23 июн. 2026 г.
- CVE-2024-756229Наблюдать
A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom a
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %revenera · installshield12 июн. 2025 г.