Skip to main content

Threats Tagged 'cwe-377'

View all threats tagged with 'cwe-377'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-377

Threats Tagged 'cwe-377'

Click on any threat for detailed analysis and mitigation recommendations

mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled location. PR 123 ignores unsafe TMPDIR values in privileged contexts and rejects empty TMPDIR. This issue has been patched in version 2.7.8.

Join the discussion

Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tampering.

Join the discussion

CVE-2026-47852 is a high-severity vulnerability in Spring AI versions 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and 2.0.0. It allows a local attacker on a multi-user system to pre-create a deterministic cache path and place a malicious ONNX model file, potentially leading to integrity compromise. The vulnerability is related to insecure handling of temporary files (CWE-377). No official patch or remediation guidance is currently available.

Join the discussion

Faktory versions prior to 1.10.0 contain an insecure temporary file vulnerability in the embedded Redis bootstrapper. The service writes its startup configuration to a fixed, world-writable path (/tmp/redis.conf) without proper validation, allowing local unprivileged users to supply malicious Redis directives. This can expose the job queue over an unauthenticated network port and enable arbitrary code execution as root via a malicious loadmodule directive. The issue is fixed in version 1.10.0.

Join the discussion

Etherpad-lite versions prior to 3.1.0 use Math.random() to generate temporary filenames for import/export operations in a shared temporary directory. This allows a local unprivileged attacker to predict these filenames and create symbolic links that cause the Etherpad process to overwrite arbitrary files with attacker-controlled content. The vulnerability is fixed in version 3.1.0.

Join the discussion

CVE-2026-53759 is an insecure temporary file vulnerability in linuxfabrik monitoring-plugins prior to version 4.2.0. The vulnerability arises because the db_sqlite.py module creates SQLite database files at predictable paths in the shared /tmp directory and follows attacker-created symbolic links. A local attacker with monitoring account access can exploit this to cause a root process to overwrite arbitrary files, cause denial of service, or manipulate SQLite databases. The issue is fixed in version 4.2.0 by moving plugin caches to a secured per-user directory.

Join the discussion

A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.

Join the discussion

CVE-2026-16791 is a low-severity vulnerability in Lenovo XClarity Essentials OneCLI for Linux versions 5.5.0 and below. It involves insecure temporary file creation that could allow a local low-privileged attacker to overwrite or truncate arbitrary local files when the program is run with elevated privileges. The vulnerability does not impact confidentiality but can affect integrity and availability. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.

Join the discussion

Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.

Join the discussion

Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the /copy command. This vulnerability is fixed in 2.1.128.

Join the discussion

Showing 1 to 10 of 28 results

Filters:Tag: cwe-377
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses