Threats Tagged 'cwe-379'
View all threats tagged with 'cwe-379'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-379'
Click on any threat for detailed analysis and mitigation recommendations
In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent reuses it based only on an existence and/or file-type check, without validating its owner or permissions. A local, unprivileged user with write access to the same base directory (by default under `$TMPDIR/ankaios`, e.g. shared `/tmp`) can pre-create this path hierarchy, including the two Control Interface FIFOs, before the agent starts. The agent then treats the attacker-owned FIFOs as the legitimate Control Interface for the targeted workload. The attacker can complete the Control Interface handshake and issue requests using that workload's configured `controlInterfaceAccess` permissions, allowing impersonation of the workload and, depending on its configured permissions, unauthorized reading and/or modification of the cluster's desired state. Join the discussion | CVE Database V5 | 09/14/2026, 17:44:56 UTC Added: 09/14/2026, 18:32:13 UTC |
0 Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:15:43 UTC Added: 09/08/2026, 17:25:20 UTC |
0 CVE-2026-85028 is a vulnerability in the AWS FPGA Development Kit (aws-fpga) prior to version 2.3.4. It involves the creation of a temporary file in a directory with insecure permissions, which may allow local users to execute arbitrary code with root privileges. This occurs because the installation component reads crafted shell content from a predictable path in a world-writable temporary directory after elevating its privileges. The issue has been fixed in version 2.3.4 by removing the vulnerable code and changing how the SDK tools source necessary functions. Workarounds include removing or commenting out references to the vulnerable temporary file in specific installation scripts. Join the discussion | AWS Security Bulletins | 09/03/2026, 18:20:07 UTC Added: 09/03/2026, 18:34:16 UTC |
0 CVE-2026-82346 is a high-severity vulnerability in HP ImageDiags prior to version 5.0.0.36. It involves the creation of temporary files in directories with insecure permissions, potentially allowing a local attacker to escalate privileges due to insufficient access controls. The vulnerability requires local access and user interaction to exploit. No official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 08/31/2026, 20:35:39 UTC Added: 08/31/2026, 20:53:04 UTC |
0 Dell Alienware Area 51m R2 BIOS contains a vulnerability involving improper link resolution before file access, allowing a low privileged local attacker to potentially perform arbitrary writes. This issue arises from the creation of temporary files in directories with insecure permissions. The vulnerability has a medium severity rating with a CVSS score of 6.6. Join the discussion | CVE Database V5 | 08/24/2026, 19:40:03 UTC Added: 08/24/2026, 19:52:54 UTC |
0 Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities. Join the discussion | CVE Database V5 | 08/24/2026, 16:00:23 UTC Added: 08/24/2026, 16:07:54 UTC |
0 NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` lives at `C:\ProgramData\LuminalShine\config\apps.json` and is created by the `SYSTEM` service. Under Windows' default `C:\ProgramData` inheritance, that gives `BUILTIN\Users` only Read+Execute — not writable — so the canonical EoP doesn't actually trigger on a vanilla install. Version 26.05.0-rc4 contains a patch for the issue. As a workaround, use default condition DACLs for `ProgramData`. Join the discussion | CVE Database V5 | 08/12/2026, 23:18:03 UTC Added: 08/12/2026, 23:27:01 UTC |
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restrictions on this directory, a local standard user can create the trigger file and provide a path to a directory containing malicious JSON instructions. The service subsequently executes the utility UpdaterAction.exe with SYSTEM privileges, which parses the instructions and performs an unvalidated file copy from a user-controlled source to a protected system destination (e.g., overwriting a service binary). This leads to full system compromise as the service automatically restarts the overwritten binary with SYSTEM privileges. Join the discussion | CVE Database V5 | 07/22/2026, 09:42:34 UTC Added: 07/22/2026, 10:08:11 UTC |
0 A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability. Join the discussion | CVE Database V5 | 06/24/2026, 19:47:15 UTC Added: 06/24/2026, 20:31:29 UTC |
0 Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directory could prepare the expected package location before another user runs pi with a temporary extension package source. Pi could then load attacker-controlled extension code in the victim user's process. This vulnerability is fixed in 0.78.1. Join the discussion | CVE Database V5 | 06/23/2026, 19:25:04 UTC Added: 06/24/2026, 13:54:31 UTC |
Showing 1 to 10 of 20 results