CWE-377
CWE-377 · 3 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-377, highest CVSS first.
- HIGH 7.9CVE-2026-79899
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to…
- LOW 3.9CVE-2026-16791
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed wit…
- UNSCOREDCVE-2026-54584public PoC
mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redire…