CWE-377

Insecure Temporary File

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

89 vulnerabilities with CWE-377
CVE-2018-3710 HIGH
Gitlab < 9.5.10 - Path Traversal
CVSS 7.8
CVE-2018-1053 HIGH
PostgreSQL <10.2 - Info Disclosure
CVSS 7.0
CVE-2017-20147 MEDIUM
SmokePing <2.7.3-r1 - DoS
CVSS 6.5
CVE-2017-16024 MEDIUM
Sync-exec < 0.6.2 - Information Disclosure
CVSS 6.5
CVE-2017-15111 MEDIUM
Keycloak-httpd-client-install < 0.8 - Symlink Following
CVSS 5.5
CVE-2017-7549 MEDIUM
Red Hat OpenStack - Symbolic-Link Attack
CVSS 6.4
CVE-2017-7560 MEDIUM
RHEL - DoS
CVSS 5.5
CVE-2016-9595 HIGH
Theforeman Katello < 3.4.0 - Symlink Following
CVSS 7.3
CVE-2015-0849 LOW
pycode-browser <1.0 - Info Disclosure
CVSS 3.9
CVE-2015-5224 CRITICAL
util-linux - File Name Collision
CVSS 9.8
CVE-2013-4253 HIGH
Redhat Openshift - Exposure to Wrong Actor
CVSS 7.5
CVE-2013-4561 CRITICAL
OpenShift - Info Disclosure
CVSS 9.1
CVE-2012-2666 CRITICAL
golang/go <1.0.2 - Code Injection
CVSS 9.8
CVE-2011-4119 CRITICAL
caml-light <= 0.75 - Buffer Overflow
CVSS 9.8
Details
Vulnerabilities 89