CWE-377
104 CVEs • Abstraction: Class
Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
CVEs (104)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary...Show more |
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when run...Show more |
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on sy...Show more |
A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the res...Show more |
A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbitrary system files affecting the integrity of the system. This issue affects: All versions of PAN-OS...Show more |
An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite system files. This issue affects Palo Alto Networks Traps 5.0 versions be...Show more |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreJun 17, 2026 Mar 16, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a...Show more |
A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root...Show more |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreJun 17, 2026 Mar 11, 2020 N/A· v4 5.0 MEDIUM· v3 3.7 LOW· v2 A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temp...Show more |
In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection |
If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine. |
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files. |
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection |
Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installation in Linux via unspecified vectors. |
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions. |
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions. |
2Redhat Theforeman3Katello SatelliteSatellite CapsuleNov 21, 2024 Jul 27, 2018 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the con...Show more |
2Nodejs Sync Exec Project2Node.js Sync ExecNov 21, 2024 Jun 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp director...Show more |
2Debian Gitlab2Debian Linux GitlabNov 21, 2024 Mar 21, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution. |
4Canonical DebianPostgresql+1 more4Cloudforms Debian LinuxPostgresql+1 moreNov 21, 2024 Feb 9, 2018 N/A· v4 7.0 HIGH· v3 3.3 LOW· v2 In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under um...Show more |