VYPR

CWE-377

Insecure Temporary File

ClassIncomplete

Description

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-149 · CAPEC-155

CVEs mapped to this weakness (128)

page 3 of 7
  • CVE-2022-34387MedFeb 11, 2023
    risk 0.42cvss 6.4epss 0.00

    Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and…

  • CVE-2022-26386MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in /tmp, but this behavior was changed to download them to /tmp where they could be affected by other local users. This behavior was reverted to the…

  • CVE-2017-20147MedSep 20, 2022
    risk 0.42cvss 6.5epss 0.01

    In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a PID file that is writable by the smokeping user. By writing arbitrary PIDs to that file, the smokeping user can cause a denial of service to arbitrary PIDs when the service is stopped.

  • CVE-2022-0315HigMar 24, 2022
    risk 0.42cvss 7.5epss 0.01

    Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.

  • CVE-2022-0736HigFeb 23, 2022
    risk 0.42cvss 7.5epss 0.02

    Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.

  • CVE-2017-16024MedJun 4, 2018
    risk 0.42cvss 6.5epss 0.03

    The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain…

  • CVE-2017-7549MedSep 21, 2017
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local…

  • CVE-2026-73585MedAug 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an…

  • CVE-2026-73584MedAug 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to…

  • CVE-2026-63404HigAug 25, 2026
    risk 0.40cvss —epss 0.00

    Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup…

  • CVE-2026-45384MedJun 10, 2026
    risk 0.40cvss 6.1epss 0.00

    bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive update. This issue has been patched in…

  • CVE-2026-40979MedApr 28, 2026
    risk 0.40cvss 6.1epss 0.00

    In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

  • CVE-2026-20651MedMar 25, 2026
    risk 0.40cvss 6.2epss 0.00

    A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.

  • CVE-2016-9595HigJul 27, 2018
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

  • CVE-2026-49135HigJun 1, 2026
    risk 0.39cvss 7.1epss 0.00

    CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by exploiting predictable file paths in the release notarization workflow. Attackers with access to the…

  • CVE-2026-49134HigJun 1, 2026
    risk 0.39cvss 7.1epss 0.00

    CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates a temporary file with mktemp, writes a…

  • CVE-2024-45339HigJan 28, 2025
    risk 0.39cvss 7.1epss 0.00

    When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink…

  • CVE-2023-49347MedDec 14, 2023
    risk 0.39cvss 6.0epss 0.00

    Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may read private information from…

  • CVE-2023-49346MedDec 14, 2023
    risk 0.39cvss 6.0epss 0.00

    Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file…

  • CVE-2023-49345MedDec 14, 2023
    risk 0.39cvss 6.0epss 0.00

    Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file…