CWE-367— Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.— MITRE CWE catalog
700 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-367page 8 of 14
- CVE-2024-30088CRITICALCVSS 7.0EG 9.0⚠ KEV2024-06-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-30099HIGHCVSS 7.0EG 7.02024-06-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-30471LOWCVSS 3.7EG 3.72024-07-17
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with the same email address until the email a…
- CVE-2024-32482LOWCVSS 2.2EG 2.22024-04-23
The Tillitis TKey signer device application is an ed25519 signing tool. A vulnerability has been found that makes it possible to disclose portions of the TKey’s data in RAM over the USB interface. To exploit the vulnerability an attacker…
- CVE-2024-3290HIGHCVSS 8.2EG 8.22024-05-17
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host
- CVE-2024-3292HIGHCVSS 8.2EG 8.22024-05-17
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. …
- CVE-2024-34528HIGHCVSS 7.7EG 7.72024-05-06
WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation.
- CVE-2024-35265HIGHCVSS 7.0EG 7.02024-06-11
Windows Perception Service Elevation of Privilege Vulnerability
- CVE-2024-36304HIGHCVSS 7.8EG 7.82024-06-10
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability …
- CVE-2024-36311MEDIUMCVSS 4.6EG 4.62026-02-10
A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality,…
- CVE-2024-37181LOWCVSS 2.6EG 2.62025-01-16
Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable information disclosure via adjacent access.
- CVE-2024-38153HIGHCVSS 7.8EG 7.82024-08-13
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-38186HIGHCVSS 7.8EG 7.82024-08-13
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- CVE-2024-38406HIGHCVSS 7.8EG 7.82024-11-04
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
- CVE-2024-38407HIGHCVSS 7.8EG 7.82024-11-04
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
- CVE-2024-38418HIGHCVSS 7.8EG 7.82025-02-03
Memory corruption while parsing the memory map info in IOCTL calls.
- CVE-2024-39420HIGHCVSS 7.0EG 7.82024-08-14
Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could…
- CVE-2024-39425HIGHCVSS 7.0EG 7.02024-08-14
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploitation of this issu…
- CVE-2024-39821MEDIUMCVSS 6.6EG 6.62024-07-15
Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a denial of service via local access.
- CVE-2024-39826MEDIUMCVSS 6.8EG 6.82024-07-15
Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access.
- CVE-2024-39894HIGHCVSS 7.5EG 7.52024-07-02
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occu…
- CVE-2024-39936HIGHCVSS 8.6EG 8.62024-07-04
An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too earl…
- CVE-2024-41779CRITICALCVSS 9.8EG 9.82024-11-22
IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vuln…
- CVE-2024-41787CRITICALCVSS 9.8EG 9.82025-01-10
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerabil…
- CVE-2024-41917HIGHCVSS 7.5EG 7.52025-02-12
Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-42107MEDIUMCVSS 4.7EG 4.72024-07-30
In the Linux kernel, the following vulnerability has been resolved: ice: Don't process extts if PTP is disabled The ice_ptp_extts_event() function can race with ice_ptp_release() and result in a NULL pointer dereference which leads to a …
- CVE-2024-42444HIGHCVSS 7.5EG 7.52025-01-14
APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead to execution of arbitrary code on the target device.
- CVE-2024-42446HIGHCVSS 7.5EG 7.52025-05-13
APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerability may lead to arbitrary code execution.
- CVE-2024-43067HIGHCVSS 7.8EG 7.82025-04-07
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
- CVE-2024-43452HIGHCVSS 7.5EG 7.52024-11-12
Windows Registry Elevation of Privilege Vulnerability
- CVE-2024-43511HIGHCVSS 7.0EG 7.02024-10-08
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-43882HIGHCVSS 7.0EG 7.02024-08-21
In the Linux kernel, the following vulnerability has been resolved: exec: Fix ToCToU between perm check and set-uid/gid usage When opening a file for exec via do_filp_open(), permission checking is done against the file's metadata at tha…
- CVE-2024-45120LOWCVSS 3.1EG 3.12024-10-10
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to a security feature bypass. An attacker could exploit this vuln…
- CVE-2024-45560HIGHCVSS 7.8EG 7.82025-02-03
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
- CVE-2024-45565HIGHCVSS 7.8EG 7.82025-05-06
Memory corruption when blob structure is modified by user-space after kernel verification.
- CVE-2024-47494MEDIUMCVSS 5.9EG 5.92024-10-11
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the …
- CVE-2024-47813LOWCVSS 2.9EG 2.92024-10-09
Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race condition, leading to panics and potent…
- CVE-2024-48322HIGHCVSS 8.1EG 8.12024-11-11
UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.
- CVE-2024-48394HIGHCVSS 7.8EG 7.82025-02-05
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which could allow an unprivileged user to exploit this flaw and gain SYSTEM-level access on the device. The vulnerability af…
- CVE-2024-49046HIGHCVSS 7.8EG 7.82024-11-12
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
- CVE-2024-49768CRITICALCVSS 9.1EG 9.12024-10-29
Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (defaults to 8192) long, followed by a secondary request using HTTP pipelining. When request lookahead is d…
- CVE-2024-49998MEDIUMCVSS 4.7EG 4.72024-10-21
In the Linux kernel, the following vulnerability has been resolved: net: dsa: improve shutdown sequence Alexander Sverdlin presents 2 problems during shutdown with the lan9303 driver. One is specific to lan9303 and the other just happens…
- CVE-2024-50220MEDIUMCVSS 4.7EG 4.72024-11-09
In the Linux kernel, the following vulnerability has been resolved: fork: do not invoke uffd on fork if error occurs Patch series "fork: do not expose incomplete mm on fork". During fork we may place the virtual memory address space int…
- CVE-2024-50234HIGHCVSS 7.0EG 7.02024-11-09
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlegacy: Clear stale interrupts before resuming device iwl4965 fails upon resume from hibernation on my laptop. The reason seems to be a stale interrupt which isn…
- CVE-2024-50379CRITICALCVSS 9.8EG 9.82024-12-17
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue …
- CVE-2024-50592HIGHCVSS 7.0EG 7.02024-11-08
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in the Elefant Update Service during the repair or update process. When using…
- CVE-2024-51563MEDIUMCVSS 6.5EG 6.52024-11-12
The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.
- CVE-2024-53016MEDIUMCVSS 6.6EG 6.62025-06-03
Memory corruption while processing I2C settings in Camera driver.
- CVE-2024-53018MEDIUMCVSS 6.6EG 6.62025-06-03
Memory corruption may occur while processing the OIS packet parser.
- CVE-2024-53028HIGHCVSS 7.8EG 7.82025-03-03
Memory corruption may occur while processing message from frontend during allocation.
Map vulnerabilities like CWE-367 to your infrastructure
EchelonGraph correlates every CVE — across CWE-367 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →