CWE-367
Medium likelihoodTime-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
649 vulnerabilities with CWE-367
CVE-2024-6601
MEDIUM
Firefox < 128 and Thunderbird < 128 - Race Condition Leading to Cross-Origin Permission Escalation
CVSS 4.7
CVE-2024-39936
HIGH
Qt < 5.15.18 - Time-of-check Time-of-use Race Condition in HTTP2 Connection Handling
CVSS 8.6
CVE-2024-39894
HIGH
OpenSSH 9.5-9.7 - Time-of-check Time-of-use Race Condition in ObscureKeystrokeTiming
CVSS 7.5
CVE-2024-0171
MEDIUM
Dell PowerEdge Server BIOS < 1.8.3 - Time-of-check Time-of-use Race Condition
CVSS 5.3
CVE-2024-5558
MEDIUM
Schneider Electric SpaceLogic AS-B and AS-P Firmware < 6.0.1 - Privilege Escalation via TOCTOU Race Condition
CVSS 6.4
CVE-2024-35265
HIGH
Windows Perception Service - Elevation of Privilege via Time-of-check Time-of-use Race Condition
CVSS 7.0
CVE-2024-30099
HIGH
Windows Kernel - Privilege Escalation
CVSS 7.0
CVE-2024-30088
HIGH
KEV
Windows Kernel - Privilege Escalation
CVSS 7.0
CVE-2024-30084
HIGH
Windows Kernel-Mode Driver - Privilege Escalation
CVSS 7.0
CVE-2024-36304
HIGH
Trend Micro Apex One/Apex One as a Service - Privilege Escalation
CVSS 7.8
CVE-2024-3292
HIGH
Nessus <unknown> - Privilege Escalation
CVSS 8.2
CVE-2024-3290
HIGH
Nessus < 10.7.3 - Authenticated Time-of-check Time-of-use Race Condition
CVSS 8.2
CVE-2024-21792
MEDIUM
Intel(R) Neural Compressor <2.5.0 - Info Disclosure
CVSS 4.7
CVE-2024-28137
HIGH
CHARX SEC-3000/3050/3100/3150 Firmware < 1.5.1 - Local Privilege Escalation via Init Script TOCTOU
CVSS 7.8
CVE-2024-29149
HIGH
Alcatel-Lucent ALE NOE deskphones <86x8_NOE-R300.1.40.12.4180 - Pri...
CVSS 7.4
CVE-2024-2913
MEDIUM
mintplex-labs/anything-llm - Info Disclosure
CVSS 6.5
CVE-2024-34528
HIGH
WordOps < 3.21.0 - Time-of-check Time-of-use Race Condition in Stack Pref Plugin
CVSS 7.7
CVE-2024-26974
HIGH
Linux kernel - crypto: qat - Use After Free
CVSS 7.0
CVE-2024-23463
HIGH
Zscaler Client Connector <4.2.1 - Auth Bypass
CVSS 8.8
CVE-2024-32482
LOW
Tillitis TKey signer device <1.0.0 - Info Disclosure
CVSS 2.2
CVE-2024-2440
MEDIUM
GitHub Enterprise Server <3.13 - Privilege Escalation
CVSS 5.5
CVE-2024-24995
HIGH
Ivanti Avalanche <6.4.3 - Privilege Escalation
CVSS 7.5
CVE-2024-24993
HIGH
Ivanti Avalanche <6.4.3 - Privilege Escalation
CVSS 7.5
CVE-2024-28718
CRITICAL
OpenStack Magnum - Remote Code Execution via cert_manager.py TOCTOU Race Condition
CVSS 9.8
CVE-2024-29066
HIGH
Windows Server 2008/2012/2016/2019/2022 RCE via DFS TOCTOU Race Condition
CVSS 7.2
Details
Vulnerabilities
649
Exploit Likelihood
Medium