CWE-367
696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (696)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition...Show more |
1Qualcomm 29Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQmp1000 Firmware+26 moreJun 17, 2026 Jun 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC. |
1Qualcomm 19Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSdm429w Firmware+16 moreJun 17, 2026 Jun 3, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Memory corruption may occur while processing the OIS packet parser. |
1Qualcomm 34Fastconnect 6800 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+31 moreJun 17, 2026 Jun 3, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Memory corruption while processing I2C settings in Camera driver. |
Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root. |
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint ca...Show more |
containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily...Show more |
1Zoom 6Meeting Software Development Kit RoomsRooms Controller+3 moreJun 17, 2026 May 14, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
Time-of-check time-of-use race condition in the UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to enable escalation of privilege via local access. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 May 13, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network. |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 May 13, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally. |
APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerability may lead to arbitrary code execution. |
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the...Show more |
Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of...Show more |
Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary...Show more |
Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (alrea...Show more |
Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerabil...Show more |
Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user...Show more |
1Qualcomm 4Sdm429w Firmware Snapdragon 429 Mobile FirmwareWcn3620 Firmware+1 moreJun 17, 2026 May 6, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Memory corruption when blob structure is modified by user-space after kernel verification. |
Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected Tesla Model S vehicles. Authentication is n...Show more |