CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

651 vulnerabilities with CWE-367
CVE-2019-7347 HIGH
ZoneMinder <1.32.3 - Privilege Escalation
CVSS 7.5
CVE-2019-7249 CRITICAL
Keybase <2.12.6 - Privilege Escalation
CVSS 9.8
CVE-2018-16872 MEDIUM
qemu < 3.1.0 - Time-of-check Time-of-use Race Condition in MTP File Handling
CVSS 5.3
CVE-2018-8584 HIGH
Windows 10 and Windows Server 2016/2019 - Elevation of Privilege via ALPC
CVSS 7.8
CVE-2018-6693 MEDIUM
McAfee Endpoint Security for Linux Threat Prevention <=10.5.1 - Unauthenticated Arbitrary File Deletion via TOCTOU
CVSS 5.3
CVE-2018-8449 LOW
Windows 10 and Windows Server 2016 - Security Feature Bypass via Device Guard File Validation
CVSS 3.3
CVE-2018-1121 LOW
procps < 3.3.15 - Process Hiding via Race Condition in /proc/PID Enumeration
CVSS 3.9
CVE-2018-0966 LOW
Windows 10 and Windows Server 2016 - Device Guard Security Feature Bypass via TOCTOU Race Condition
CVSS 3.3
CVE-2017-18869 LOW
chownr < 1.1.0 - Time-of-check Time-of-use Race Condition via Symlink Attack
CVSS 2.5
CVE-2017-15404 HIGH
Google Chrome < 61.0.3163.113 - Local Privilege Escalation via Crash Dump Symlink Handling
CVSS 7.8
CVE-2017-11830 MEDIUM
Windows - Privilege Escalation
CVSS 5.3
CVE-2017-0756 HIGH
Android 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2 - Remote Code Execution in Media Framework
CVSS 7.8
CVE-2017-0331 HIGH
Android < 7.1.1 - Elevation of Privilege via NVIDIA Video Driver Race Condition
CVSS 7.8
CVE-2017-0412 HIGH
Android 7.0, 7.1.1 - Privilege Escalation via Framework APIs Race Condition
CVSS 7.8
CVE-2017-0411 HIGH
Android 7.0 7.1.1 - Elevation of Privilege via Framework APIs Race Condition
CVSS 7.8
CVE-2015-7810 MEDIUM
libbluray < 0.8.0 - Time-of-check Time-of-use Race Condition in MountManager JAR Expansion
CVSS 4.7
CVE-2015-1865 MEDIUM
coreutils 8.4 - Arbitrary File Deletion via Race Condition in fts.c
CVSS 5.1
CVE-2015-1743
Microsoft Internet Explorer 7-11 - Privilege Escalation via TOCTOU Race Condition
CVE-2013-4235 MEDIUM
shadow - Time-of-check Time-of-use Race Condition when Copying and Removing Directory Trees
CVSS 4.7
CVE-2013-3888 HIGH
Microsoft Windows 7 - TOCTOU Race Condition
CVSS 8.4
CVE-2012-5630 MEDIUM
libuser 0.56-0.57 - Time-of-check Time-of-use Race Condition
CVSS 6.3
CVE-2011-10035 HIGH
Nagios XI < 2011R1.9 - Privilege Escalation via Crontab Install Script Race Condition
CVSS 7.0
CVE-2011-4126 HIGH
calibre - Time-of-check Time-of-use Race Condition in linux_mount_helper
CVSS 8.1
CVE-2005-1111 MEDIUM
cpio <2.6 - Local Privilege Escalation
CVSS 4.7
CVE-2004-0594
PHP 4.x-5.0.0RC3 - Remote Code Execution
Details
Vulnerabilities 651
Exploit Likelihood Medium