The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:us
The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/rel
The Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/
The Tecno Camon Android device with a build fingerprint of TECNO/H612/TECNO-ID5a:8.1.0/O11019/F-180828V106:user/release-
The Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-k
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious i
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpReques
ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflic
An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped
Monkey HTTP Daemon has local security bypass
In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environme
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to ve
Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted pag
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which co
LibreOffice and OpenOffice automatically open embedded content
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical
Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Arbitrary File Write due to Cavwp.exe handling of Comodo's
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary fi
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata update
Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and a
A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D wit
The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that th
Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token i
An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/sys
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Ente
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise M
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM96
A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.2
This vulnerability allows remote attackers to execute code by overwriting arbitrary files on vulnerable installations of
This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of Ne
This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of Ne
Insufficient Policy Enforcement in Devtools remote debugging in Google Chrome prior to 62.0.3202.62 allowed a remote att
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory
Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iC
An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user c
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/in
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started