CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

704 vulnerabilities with CWE-367
CVE-2024-13944 HIGH
Norton Utilities Ultimate <24.2.16862.6344 - Privilege Escalation
CVSS 7.8
CVE-2024-45565 HIGH
Qualcomm SDM429W Firmware - Memory Corruption via TOCTOU Race Condition
CVSS 7.8
CVE-2024-6029 MEDIUM
Tesla Model S Firmware < 2024.2.3 - Unauthenticated Firewall Bypass via Race Condition in Iris Modem
CVSS 5.0
CVE-2024-43067 HIGH
Microcontroller <version> - Memory Corruption
CVSS 7.8
CVE-2024-54084 HIGH
AMI APTIO V 5.0-5.038 - Time-of-check Time-of-use Race Condition
CVSS 7.5
CVE-2024-53694 HIGH
QVPN Device Client for Mac <2.2.5, Qsync for Mac <5.1.3, Qfinder Pr...
CVE-2024-53032 HIGH
Qualcomm Firmware - Memory Corruption via Guest VM Keyboard Interaction
CVSS 7.8
CVE-2024-53028 HIGH
Qualcomm QAM8255P and related firmware - Memory Corruption via Frontend Message Processing
CVSS 7.8
CVE-2024-41917 HIGH
Intel(R) Battery Life Diagnostic Tool <2.4.1 - Privilege Escalation
CVSS 7.5
CVE-2024-48394 HIGH
NDD Print <5.24.3 - Privilege Escalation
CVSS 7.8
CVE-2024-45560 HIGH
Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via Unvalidated Userspace Buffer
CVSS 7.8
CVE-2024-38418 HIGH
Kernel <version> - Memory Corruption
CVSS 7.8
CVE-2024-37181 LOW
Intel(R) Neural Compressor <v3.0 - Info Disclosure
CVSS 2.6
CVE-2024-42444 HIGH
AMI APTIO V 5.0-5.038 - TOCTOU Race Condition
CVSS 7.5
CVE-2024-41787 CRITICAL
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 - Remote Code Execution via Race Condition
CVSS 9.8
CVE-2024-56337 CRITICAL
Apache Tomcat 9.0.0-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - Time-of-check Time-of-use Race Condition
CVSS 9.8
CVE-2024-50379 CRITICAL
Apache Tomcat 9.0.0-9.0.97, 10.1.0-M1-10.1.33, 11.0.0-M1-11.0.1 - RCE via TOCTOU Race Condition in JSP Compilation
CVSS 9.8
CVE-2024-10972 HIGH
Velocidex WinPmem <4.1 - Improper Input Validation
CVSS 7.3
CVE-2024-53289 HIGH
Dell ThinOS 2408 - Time-of-check Time-of-use Race Condition
CVSS 7.8
CVE-2024-27134 HIGH
MLflow < 2.16.0 - Local Privilege Escalation via Spark UDF ToCToU Race Condition
CVSS 7.0
CVE-2024-41779 CRITICAL
IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2-7.0.3 - Remote Code Execution via Race Condition
CVSS 9.8
CVE-2024-22185 HIGH
Intel(R) processor <ACTM - Privilege Escalation
CVSS 7.2
CVE-2024-49046 HIGH
Windows 10 1507-22H2 and Windows 11 22H2 - Elevation of Privilege via Win32 Kernel Subsystem Race Condition
CVSS 7.8
CVE-2024-43452 HIGH
Windows 10/11 Elevation of Privilege via Registry TOCTOU Race Condition
CVSS 7.5
CVE-2024-51563 MEDIUM
virtio-vq-recordon - Use After Free
CVSS 6.5
Details
Vulnerabilities 704
Exploit Likelihood Medium