CWE-367— Time-of-check Time-of-use (TOCTOU) Race Condition
597 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-367page 9 of 12
- CVE-2024-5803HIGHCVSS 7.5EG 7.52024-10-03
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.
- CVE-2024-6029MEDIUMCVSS 5.0EG 5.02025-04-30
Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected Tesla Model S vehicles. Authentication is not required to expl…
- CVE-2024-6601MEDIUMCVSS 4.7EG 4.72024-07-09
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
- CVE-2024-6787MEDIUMCVSS 5.3EG 5.32024-09-21
This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbitrary files to the system. This could al…
- CVE-2024-7348HIGHCVSS 8.8EG 8.82024-08-08
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation …
- CVE-2024-7531MEDIUMCVSS 6.5EG 6.52024-08-06
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is …
- CVE-2024-9183HIGHCVSS 7.7EG 7.72025-12-05
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged user…
- CVE-2024-9512MEDIUMCVSS 5.3EG 5.32025-06-12
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary n…
- CVE-2025-0759LOWCVSS 3.3EG 3.32025-02-27
IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization.
- CVE-2025-13032CRITICALCVSS 9.9EG 9.92025-11-11
Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privelages via pool overflow.
- CVE-2025-13818MEDIUMCVSS 6.7EG 6.72026-02-06
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
- CVE-2025-20037HIGHCVSS 7.2EG 7.22025-08-12
Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2025-20074HIGHCVSS 7.8EG 7.82025-08-12
Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-20082HIGHCVSS 7.5EG 7.52025-05-13
Time-of-check time-of-use race condition in the UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to enable escalation of privilege via local access.
- CVE-2025-20740MEDIUMCVSS 4.7EG 4.72025-11-04
In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR0043…
- CVE-2025-21191HIGHCVSS 7.0EG 7.02025-04-08
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
- CVE-2025-21431MEDIUMCVSS 5.5EG 5.52025-04-07
Information disclosure may be there when a guest VM is connected.
- CVE-2025-21455HIGHCVSS 7.8EG 7.82025-08-06
Memory corruption while submitting blob data to kernel space though IOCTL.
- CVE-2025-21473HIGHCVSS 7.8EG 7.82025-08-06
Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
- CVE-2025-21485HIGHCVSS 7.8EG 7.82025-06-03
Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.
- CVE-2025-21746MEDIUMCVSS 4.7EG 5.52025-02-27
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics - fix crash when enabling pass-through port When enabling a pass-through port an interrupt might come before psmouse driver binds to the pass-through po…
- CVE-2025-21958MEDIUMCVSS 4.7EG 4.72025-04-01
In the Linux kernel, the following vulnerability has been resolved: Revert "openvswitch: switch to per-action label counting in conntrack" Currently, ovs_ct_set_labels() is only called for confirmed conntrack entries (ct) within ovs_ct_c…
- CVE-2025-21998MEDIUMCVSS 4.7EG 4.72025-04-03
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registration race Since the conversion to using the TZ allocator, the efivars service is registered before the memory pool has be…
- CVE-2025-22060MEDIUMCVSS 4.7EG 4.72025-04-16
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: Prevent parser TCAM memory corruption Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM information, from concurrent modifications. Both the…
- CVE-2025-22224CRITICALCVSS 9.3EG 9.3⚠ KEV2025-03-04
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute c…
- CVE-2025-22394MEDIUMCVSS 6.7EG 6.72025-01-15
Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code executio…
- CVE-2025-23279HIGHCVSS 7.0EG 7.02025-08-02
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, in…
- CVE-2025-23359HIGHCVSS 8.3EG 8.32025-02-12
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vu…
- CVE-2025-24036HIGHCVSS 7.0EG 7.02025-02-11
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
- CVE-2025-2425MEDIUMCVSS 5.1EG 0.02025-07-18
Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system.
- CVE-2025-24430LOWCVSS 3.7EG 3.72025-02-11
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could e…
- CVE-2025-24432LOWCVSS 3.7EG 3.72025-02-11
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could e…
- CVE-2025-26620MEDIUMCVSS 6.3EG 0.02025-02-18
Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.AccessTokenManagement contains a race condition when requesting access tokens using the client credentials flow. Concurrent …
- CVE-2025-27076HIGHCVSS 7.8EG 7.82025-08-06
Memory corruption while processing simultaneous requests via escape path.
- CVE-2025-27725MEDIUMCVSS 4.4EG 4.42025-11-11
Time-of-check time-of-use race condition for some ACAT before version 3.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack ma…
- CVE-2025-27812HIGHCVSS 8.1EG 8.12025-04-10
MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.
- CVE-2025-29833HIGHCVSS 7.7EG 7.12025-05-13
Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.
- CVE-2025-29969HIGHCVSS 7.5EG 7.52025-05-13
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
- CVE-2025-30101MEDIUMCVSS 4.4EG 4.42025-05-08
Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to den…
- CVE-2025-30663HIGHCVSS 8.8EG 8.82025-05-14
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2025-31146MEDIUMCVSS 6.1EG 6.12025-11-11
Time-of-check time-of-use race condition for some Intel Ethernet Adapter Complete Driver Pack software before version 1.5.1.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authentic…
- CVE-2025-32441MEDIUMCVSS 4.2EG 4.22025-05-07
Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that sess…
- CVE-2025-32784HIGHCVSS 7.5EG 0.02025-04-15
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025.4.10, a race condition vulnerability has been identified in the conda-forge-webservices component used within the shar…
- CVE-2025-34027CRITICALCVSS 10.0EG 0.02025-05-21
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for …
- CVE-2025-34290HIGHCVSS 8.5EG 0.02025-12-20
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, w…
- CVE-2025-3464HIGHCVSS 8.4EG 0.02025-06-16
A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASU…
- CVE-2025-3599MEDIUMCVSS 6.5EG 6.52025-04-30
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an app…
- CVE-2025-38112MEDIUMCVSS 4.7EG 4.72025-07-03
In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_readable() sk->sk_prot->sock_is_readable is a valid function pointer when sk resides in a sockmap. After the last sk_psock_put() (which us…
- CVE-2025-38217MEDIUMCVSS 4.7EG 4.72025-07-04
In the Linux kernel, the following vulnerability has been resolved: hwmon: (ftsteutates) Fix TOCTOU race in fts_read() In the fts_read() function, when handling hwmon_pwm_auto_channels_temp, the code accesses the shared variable data->fa…
- CVE-2025-38352HIGHCVSS 7.4EG 9.0⚠ KEV2025-07-22
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls hand…
Map vulnerabilities like CWE-367 to your infrastructure
EchelonGraph correlates every CVE — across CWE-367 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →