Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-377

MITRE ↗

CWE-377

9
HIGH
14
MEDIUM
2
LOW
30 CVEs
7.5
CVE-2026-20649

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe

7.5
CVE-2025-67223

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w

7.5
CVE-2026-47852

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.

7.2
CVE-2026-44878

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r

7.1
CVE-2026-20204

In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26

7.1
CVE-2026-49134

CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers

7.1
CVE-2026-49135

CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to acces

7.0
CVE-2026-4822

A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C

7.0
CVE-2026-40973

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTe

6.7
CVE-2025-14612

Insecure Temporary File vulnerability in Altera Quartus Prime Pro  Installer (SFX) on Windows allows : Use of Predict

6.7
CVE-2025-14614

Insecure Temporary File vulnerability in Altera Quartus Prime Standard  Installer (SFX) on Windows, Altera Quartus Pr

6.3
CVE-2026-73584

A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance

6.3
CVE-2026-73585

A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a loca

6.2
CVE-2026-20651

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.5, ma

6.1
CVE-2026-40979

In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version

6.1
CVE-2026-45384

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4

6.1
CVE-2026-46406

Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a ha

5.5
CVE-2026-20618

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be

5.3
CVE-2026-41001

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da

5.3
CVE-2026-75920

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing s

4.7
CVE-2026-41991

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp util

4.4
CVE-2026-25645

Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a

4.2
CVE-2026-55086

Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/Exp

3.9
CVE-2026-16791

A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could

3.3
CVE-2026-35342

The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp,

CVE-2026-25701

An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve

CVE-2026-62294

Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to

CVE-2026-53759

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to ve

CVE-2025-14602

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This a

CVE-2026-63404

Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vu

Frequently Asked Questions

What is CWE-377?

CWE-377 (CWE-377) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-377?

There are 30 CVE records associated with CWE-377 in our database. Of these, 0 are critical severity, 9 are high severity, and 14 are medium severity.

How can I protect against CWE-377 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-377 using AI-powered security agents.

Detect CWE-377 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-377 vulnerabilities across your infrastructure.

Get Started