CWE-377

CWE-377 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-377, highest CVSS first.

  1. HIGH 7.9CVE-2026-79899

    Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to…

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.9CVE-2026-16791

    A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed wit…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-54584public PoC

    mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redire…

    AI risk analysis on Exploit-DB.ai →