CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

649 vulnerabilities with CWE-367
CVE-2022-33907 MEDIUM
IdeBusDxe <5.2.05.27.25-<5.3 - Memory Corruption
CVSS 6.4
CVE-2022-30773 MEDIUM
IhisiSmm <5.4.23, <5.5.23 - Memory Corruption
CVSS 6.4
CVE-2022-21198 HIGH
Intel Celeron Processor BIOS Firmware - Privilege Escalation via Time-of-check Time-of-use Race Condition
CVSS 7.9
CVE-2022-32608 MEDIUM
Android - Use-After-Free via Race Condition in JPEG Component
CVSS 6.4
CVE-2022-33214 HIGH
Snapdragon Auto-Snapdragon Wearables - Memory Corruption
CVSS 8.4
CVE-2022-22225 MEDIUM
Juniper Networks Junos OS/Junos OS Evolved - DoS
CVSS 5.9
CVE-2022-22220 MEDIUM
Juniper Networks Junos OS/Junos OS Evolved - DoS
CVSS 5.9
CVE-2022-41744 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.0
CVE-2022-29800 MEDIUM
Windows Defender for Endpoint - Time-of-check Time-of-use Race Condition
CVSS 4.7
CVE-2022-25696 HIGH
Qualcomm APQ8053 Firmware - Memory Corruption via Time-of-check Time-of-use Race Condition in Display
CVSS 8.4
CVE-2022-22094 HIGH
Qualcomm AQT1000 and related firmware - Memory Corruption via Kernel Mapping Reference Race Condition
CVSS 7.8
CVE-2022-22093 HIGH
Qualcomm AQT1000 Firmware - Memory Corruption or Denial of Service via Concurrent Hypervisor IRQ Operations
CVSS 7.8
CVE-2022-26859 MEDIUM
Dell BIOS - Race Condition via SMI Input
CVSS 6.1
CVE-2022-1974 MEDIUM
Linux Kernel - Use-After-Free via NFC Core kobject Race Condition
CVSS 4.1
CVE-2022-20909 MEDIUM
Cisco Nexus Dashboard 2.0-2.2(1e) - Authenticated Privilege Escalation via CLI Command Execution
CVSS 6.0
CVE-2022-20908 MEDIUM
Cisco Nexus Dashboard 2.0-2.2(1e) - Authenticated Privilege Escalation via CLI Command Injection
CVSS 6.0
CVE-2022-20907 MEDIUM
Cisco Nexus Dashboard 2.0-2.2(1e) - Authenticated Privilege Escalation via CLI Command Execution
CVSS 6.0
CVE-2022-20906 MEDIUM
Cisco Nexus Dashboard 2.0-2.2(1e) - Authenticated Privilege Escalation via CLI Command Execution
CVSS 6.0
CVE-2022-34899 HIGH
Parallels Access 6.5.4 - Privilege Escalation via Symbolic Link Race Condition
CVSS 7.8
CVE-2022-33691 MEDIUM
score driver <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 6.2
CVE-2022-27904 HIGH
Automox Agent for macOS < 39 - Time-of-check Time-of-use Race Condition during Install
CVSS 7.0
CVE-2022-31466 HIGH
Quick Heal Total Security <12.1.1.27 - Privilege Escalation
CVSS 7.9
CVE-2022-1537 HIGH
gruntjs/grunt < 1.5.3 - Arbitrary File Write via TOCTOU Race Condition in file.copy
CVSS 7.0
CVE-2022-20110 HIGH
Android - Use-After-Free via Race Condition in ion
CVSS 7.0
CVE-2022-28743 CRITICAL
Foscam R2C <1.13.1.6-2.91.2.66 - Authenticated RCE
CVSS 9.1
Details
Vulnerabilities 649
Exploit Likelihood Medium