← Back
CWE-377

104 CVEs • Abstraction: Class

Insecure Temporary File

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

JSON object

Loading...

CVEs (104)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Keycloak Httpd Client Install Project
1Keycloak Httpd Client Install
Nov 21, 2024
Jan 20, 2018
N/A· v4
5.5 MEDIUM· v3
3.6 LOW· v2
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
1Openstack
1Instack Undercloud
May 13, 2026
Sep 21, 2017
N/A· v4
6.4 MEDIUM· v3
3.3 LOW· v2
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and sec...Show more
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.Show less
1Redhat
1Rhnsd
May 13, 2026
Sep 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.
1Kernel
1Util Linux
May 13, 2026
Aug 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.