CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

704 vulnerabilities with CWE-367
CVE-2022-43779 HIGH
HP PC <AMI UEFI - RCE/DoS/Info Disclosure
CVSS 7.0
CVE-2022-27538 HIGH
HP Elite and Dragonfly Firmware - Time-of-Check Time-of-Use Race Condition
CVSS 7.0
CVE-2022-34398 HIGH
Dell Alienware BIOS < 1.22.2 - Authenticated Arbitrary Code Execution via TOCTOU Race Condition
CVSS 7.5
CVE-2022-48191 HIGH
Trend Micro Maximum Security 2022 17.7 - Privilege Escalation via Mount Point Race Condition
CVSS 7.0
CVE-2022-36929 HIGH
Zoom Rooms < 5.12.7 - Local Privilege Escalation via Installer Race Condition
CVSS 7.8
CVE-2022-36927 HIGH
Zoom Rooms < 5.11.3 - Local Privilege Escalation via TOCTOU Race Condition
CVSS 8.8
CVE-2022-25716 MEDIUM
Qualcomm SD888 5G Firmware - Memory Corruption in Multimedia Framework
CVSS 6.7
CVE-2022-32638 MEDIUM
Android - Local Privilege Escalation via Race Condition in ISP
CVSS 6.4
CVE-2022-26387 HIGH
Firefox < 98 and Firefox ESR < 91.7 - Time-of-check Time-of-use Race Condition in Add-on Installation
CVSS 7.5
CVE-2022-22753 HIGH
Firefox < 97.0 and Firefox ESR < 91.6 - Time-of-Check Time-of-Use Race Condition in Maintenance Service
CVSS 7.1
CVE-2022-3590 MEDIUM
WordPress 4.2-6.1.1 - Unauthenticated Blind SSRF via Pingback TOCTOU Race Condition
CVSS 5.9
CVE-2022-44670 HIGH
Windows SSTP - Remote Code Execution via TOCTOU Race Condition
CVSS 8.1
CVE-2022-44651 HIGH
Trend Micro Apex One < 14.0.11789 - Local Privilege Escalation via TOCTOU Race Condition
CVSS 7.0
CVE-2022-39908 MEDIUM
Google Android - TOCTOU Race Condition
CVSS 6.9
CVE-2022-45842 MEDIUM
WP ULike WordPress Plugin <= 4.6.4 - Unauthenticated Race Condition
CVSS 5.3
CVE-2022-34830 HIGH
Arm Utgard GPU Kernel Driver - Time-of-check Time-of-use Race Condition
CVSS 7.5
CVE-2022-30283 HIGH
Insyde Kernel 5.0-5.4 - Time-of-check Time-of-use Race Condition in UsbCoreDxe
CVSS 7.5
CVE-2022-33986 MEDIUM
Insyde Kernel 5.4-5.4.05.44.23 - TOCTOU Race Condition in VariableRuntimeDxe SMI Handler
CVSS 6.4
CVE-2022-33985 HIGH
NvmExpressDxe <5.2.05.27.25-<5.3 - Memory Corruption
CVSS 7.0
CVE-2022-33984 HIGH
SdMmcDevice <5.2.05.27.25-<5.3.05.36.25 - Memory Corruption
CVSS 7.0
CVE-2022-33983 HIGH
NvmExpressLegacy <5.2.05.27.25 - Memory Corruption
CVSS 7.0
CVE-2022-33909 HIGH
HddPassword <5.2.05.27.23-<5.3.05.36.23 - Memory Corruption
CVSS 7.0
CVE-2022-33908 HIGH
SdHostDriver <5.2.05.27.25-<5.3.05.36.25 - Memory Corruption
CVSS 7.0
CVE-2022-33906 MEDIUM
FwBlockServiceSmm - Memory Corruption
CVSS 6.4
CVE-2022-33905 HIGH
Insyde Kernel 5.2-5.2.05.27.23 - SMRAM Corruption via AhciBusDxe DMA TOCTOU Race Condition
CVSS 7.0
Details
Vulnerabilities 704
Exploit Likelihood Medium