CWE-367
696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (696)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Nvidia 2Nvidia Container Toolkit Nvidia Gpu OperatorJun 17, 2026 Feb 12, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful...Show more |
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass....Show more |
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass....Show more |
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability |
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which could allow an unprivileged user to exploit this flaw and gain SYSTEM-level access on the device. T...Show more |
1Qualcomm 37Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+34 moreJun 17, 2026 Feb 3, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer. |
1Qualcomm 61C V2x 9150 Firmware Csrb31024 FirmwareFastconnect 6800 Firmware+58 moreJun 17, 2026 Feb 3, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Memory corruption while parsing the memory map info in IOCTL calls. |
Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable information disclosure via adjacent access. |
Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leadi...Show more |
APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead to execution of arbitrary code on the target device. |
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could expl...Show more |
2Apache Netapp2Bootstrap Os TomcatJun 17, 2026 Dec 20, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The follow...Show more |
2Apache Netapp2Bootstrap Os TomcatJun 17, 2026 Dec 17, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configura...Show more |
Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with admin access can trigger a BSOD with a parallel thread changing the memory’s access right under the...Show more |
Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privi...Show more |
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is o...Show more |
1Ibm 1Engineering Systems Design Rhapsody Jun 17, 2026 Nov 22, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could...Show more |
Time-of-check Time-of-use Race Condition in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to potentially enable escalation of privilege via local access. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Nov 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |