CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

649 vulnerabilities with CWE-367
CVE-2021-30347 CRITICAL
Qualcomm AR8035 Firmware - Time-of-check Time-of-use Race Condition
CVSS 9.1
CVE-2021-30343 CRITICAL
Qualcomm AR8035 and Multiple Firmware - Time-of-check Time-of-use Race Condition
CVSS 9.1
CVE-2021-30342 CRITICAL
Qualcomm APQ8009W Firmware - Time-of-check Time-of-use Race Condition
CVSS 9.1
CVE-2021-3969 HIGH
Lenovo System Interface Foundation < 1.1.20.3 - Privilege Escalation via TOCTOU Race Condition in IMController
CVSS 7.8
CVE-2021-3922 HIGH
Lenovo System Interface Foundation < 1.1.20.3 - Time-of-check Time-of-use Race Condition in IMController
CVSS 7.8
CVE-2021-26350 MEDIUM
AMD EPYC 7002 Series Firmware < romepi-sp3_1.0.0.d - Denial of Service via SMU Message Port Race Condition
CVSS 4.7
CVE-2021-22043 HIGH
VMware ESXi - Privilege Escalation via TOCTOU Race Condition in Temporary File Handling
CVSS 7.5
CVE-2021-4098 HIGH
Google Chrome < 96.0.4664.110 - Sandbox Escape via Mojo Data Validation Bypass
CVSS 7.4
CVE-2021-4001 MEDIUM
Linux Kernel <5.16 rc2 - Privilege Escalation
CVSS 4.1
CVE-2021-0897 MEDIUM
Google Android - Local Privilege Escalation via Missing Bounds Check in apusys
CVSS 6.7
CVE-2021-42835 HIGH
Plex Media Server < 1.25.0.5282 - Local Privilege Escalation via Update Service RPC TOCTOU Race Condition
CVSS 7.0
CVE-2021-33097 MEDIUM
Crypto API Toolkit - Privilege Escalation
CVSS 6.6
CVE-2021-1921 HIGH
Qualcomm AQT1000 Firmware - Memory Corruption via Hypervisor Unmap Operations
CVSS 7.8
CVE-2021-36924 HIGH
Realtek RtsUpx USB Utility Driver < 1.14.0.0 - Pool Overflow via Crafted Device IO Control Packet
CVSS 7.8
CVE-2021-34788 HIGH
Cisco AnyConnect Secure Mobility Client < 4.10.03104 - Authenticated Shared Library Hijacking via Race Condition
CVSS 7.0
CVE-2021-34413 HIGH
Zoom Plugin for Microsoft Outlook for macOS < 5.3.52553.0918 - Privilege Escalation via TOC/TOU Race Condition
CVSS 7.5
CVE-2021-30290 HIGH
Qualcomm Firmware - Null Pointer Dereference via Timeline Fence Race Condition
CVSS 8.4
CVE-2021-3054 HIGH
PAN-OS Authenticated RCE via Plugin Upload Race Condition
CVSS 7.2
CVE-2021-29657 HIGH
Linux Kernel 5.10-5.10.28 - Use-After-Free via Nested SVM VMCB12 Double Fetch
CVSS 7.4
CVE-2021-0289 MEDIUM
Juniper Junos OS TOCTOU Race Condition in ARP Policer Bypass
CVSS 6.5
CVE-2021-22369 HIGH
Huawei Smartphone - Privilege Escalation
CVSS 8.1
CVE-2021-32708 CRITICAL
Flysystem 1.0.0-1.1.3 - Remote Code Execution via Unicode Whitespace in File Extension
CVSS 9.8
CVE-2021-1567 HIGH
Cisco AnyConnect < 4.10.01075 Authenticated DLL Hijacking via Race Condition
CVSS 7.0
CVE-2021-20181 HIGH
QEMU <= 5.2.0 - Use-After-Free via 9pfs Server Race Condition
CVSS 7.5
CVE-2021-23892 HIGH
McAfee Endpoint Security for Linux Threat Prevention 10.5.0-10.7.5 - Privilege Escalation via TOCTOU Race Condition
CVSS 8.2
Details
Vulnerabilities 649
Exploit Likelihood Medium