A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r
In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26
CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers
CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to acces
A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTe
Insecure Temporary File vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows : Use of Predict
Insecure Temporary File vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Pr
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a loca
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.5, ma
In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4
Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a ha
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da
phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing s
GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp util
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a
Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/Exp
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp,
An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve
Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to ve
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This a
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vu
Frequently Asked Questions
What is CWE-377?
CWE-377 (CWE-377) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-377?
There are 30 CVE records associated with CWE-377 in our database. Of these, 0 are critical severity, 9 are high severity, and 14 are medium severity.
How can I protect against CWE-377 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-377 using AI-powered security agents.
Detect CWE-377 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-377 vulnerabilities across your infrastructure.
Get Started