CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

704 vulnerabilities with CWE-367
CVE-2022-31637 HIGH
HP ZBook 14u G4 Firmware - Time-of-check Time-of-use Race Condition
CVSS 7.8
CVE-2022-31636 HIGH
HP ZCentral 4R Workstation Firmware < 1.24 - Time-of-check Time-of-use Race Condition
CVSS 7.8
CVE-2022-31635 HIGH
HP ZCentral 4R Workstation Firmware < 1.24 - Time-of-check Time-of-use Race Condition
CVSS 7.8
CVE-2022-43778 HIGH
HP EliteBook 840 G3 Firmware - Time-of-check Time-of-use Race Condition
CVSS 7.8
CVE-2022-43777 HIGH
HP Z640 Workstation Firmware - Time-of-check Time-of-use Race Condition
CVSS 7.8
CVE-2022-27541 HIGH
HP EliteBook 755 G4 Firmware < 1.42 - Time-of-Check Time-of-Use Race Condition
CVSS 7.8
CVE-2022-27539 HIGH
HP EliteBook 755 G4 Firmware < 1.42 - Time-of-Check Time-of-Use Race Condition
CVSS 7.8
CVE-2022-38730 MEDIUM
Docker Desktop for Windows <4.6 - Code Injection
CVSS 6.3
CVE-2022-33270 HIGH
Qualcomm AR8035 Firmware - Denial of Service via RRC Reconfiguration Message Race Condition
CVSS 7.5
CVE-2022-43946 HIGH
Fortinet FortiClientWindows <7.0.7 - RCE
CVSS 7.5
CVE-2022-3093 MEDIUM
Tesla Vehicle Firmware 2022.16.0.3 - Physical Root Code Execution via ice_updater
CVSS 6.4
CVE-2022-36980 HIGH
Ivanti Avalanche 6.3.2.3490-6.3.4 - Authentication Bypass via Race Condition in EnterpriseServer Service
CVSS 8.1
CVE-2022-33257 CRITICAL
Qualcomm Core Firmware - Memory Corruption
CVSS 9.3
CVE-2022-32477 HIGH
Insyde InsydeH2O 5.0-5.2.05.27.27 - Time-of-check Time-of-use Race Condition in FvbServicesRuntimeDxe Shared Buffer
CVSS 7.0
CVE-2022-32475 HIGH
Insyde InsydeH2O 5.0-5.5 - Time-of-check Time-of-use Race Condition via VariableRuntimeDxe Shared Buffer
CVSS 7.0
CVE-2022-32469 HIGH
Insyde InsydeH2O 5.0-5.5 - TOCTOU Race Condition in PnpSmm Shared Buffer
CVSS 7.0
CVE-2022-32953 HIGH
Insyde InsydeH2O 5.0-5.5 - TOCTOU Race Condition in SdHostDriver Buffer
CVSS 7.0
CVE-2022-32476 HIGH
Insyde InsydeH2O 5.0-5.5 - TOCTOU Race Condition in AhciBusDxe Shared Buffer
CVSS 7.0
CVE-2022-32473 HIGH
Insyde InsydeH2O 5.0-5.5 - Time-of-check Time-of-use Race Condition in HddPassword Shared Buffer
CVSS 7.0
CVE-2022-32470 HIGH
Insyde InsydeH2O 5.0-5.5 - TOCTOU Race Condition in FwBlockServiceSmm Shared Buffer
CVSS 7.0
CVE-2022-32955 HIGH
InsydeH2O <5.6 - Privilege Escalation
CVSS 7.0
CVE-2022-32954 HIGH
InsydeH2O 5.1-5.5 - Privilege Escalation
CVSS 7.0
CVE-2022-32478 HIGH
Insyde InsydeH2O 5.0-5.5 - TOCTOU Race Condition in IdeBusDxe Shared Buffer
CVSS 7.0
CVE-2022-32474 HIGH
Insyde InsydeH2O 5.0-5.5 - Time-of-check Time-of-use Race Condition in StorageSecurityCommandDxe Shared Buffer
CVSS 7.0
CVE-2022-32471 HIGH
Insyde InsydeH2O 5.0-5.5 - Time-of-check Time-of-use Race Condition in IhisiSmm via DMA Command Buffer Manipulation
CVSS 7.0
Details
Vulnerabilities 704
Exploit Likelihood Medium