CWE-377
104 CVEs • Abstraction: Class
Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
CVEs (104)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Keycloak Httpd Client Install Project 1Keycloak Httpd Client Install Nov 21, 2024 Jan 20, 2018 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link. |
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and sec...Show more |
It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes. |
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks. |