CWE-367
696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (696)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Aug 14, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploi...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Aug 14, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulne...Show more |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 21h2+8 moreJun 17, 2026 Aug 13, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Aug 13, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Kernel Elevation of Privilege Vulnerability |
1Amd 105Epyc 7001 Firmware Epyc 7203 FirmwareEpyc 7203p Firmware+102 moreJun 17, 2026 Aug 13, 2024 N/A· v4 6.4 MEDIUM· v3 N/A· v2 A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and access to the
BIOS menu or UEFI shell to modify the communications buffer potentially
resulting in arbitrary code execution. |
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacin...Show more |
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when...Show more |
In the Linux kernel, the following vulnerability has been resolved: ice: Don't process extts if PTP is disabled The ice_ptp_extts_event() function can race with ice_ptp_release() and result in a NULL pointer dereferenc...Show more |
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with the same email addres...Show more |
1Zoom 3Meeting Software Development Kit Workplace DesktopWorkplace Virtual Desktop InfrastructureJun 17, 2026 Jul 15, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access. |
Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a denial of service via local access. |
1Zoom 3Meeting Software Development Kit RoomsWorkplace DesktopJun 17, 2026 Jul 15, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access. |
1Samsung 8Exynos 1080 Firmware Exynos 1280 FirmwareExynos 1380 Firmware+5 moreJun 17, 2026 Jul 9, 2024 N/A· v4 4.1 MEDIUM· v3 N/A· v2 A vulnerability was discovered in Samsung Mobile Processor Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, and Exynos 2400 that involves a time-of-check to time-of-use (TOCTOU) ra...Show more |
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128. |
An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection m...Show more |
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystro...Show more |
1Hp 353Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+350 moreJun 17, 2026 Jun 28, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP...Show more |
1Dell 6Poweredge C6615 Firmware Poweredge R6615 FirmwarePoweredge R6625 Firmware+3 moreJun 17, 2026 Jun 25, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources. |
1Schneider Electric 2Spacelogic As B Firmware Spacelogic As P FirmwareJun 17, 2026 Jun 12, 2024 N/A· v4 6.4 MEDIUM· v3 N/A· v2 CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could
cause escalation of privileges when an attacker abuses a limited admin account. |
1Microsoft 7Windows 10 1809 Windows 10 21h2Windows 10 22h2+4 moreJul 20, 2026 Jun 11, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 Windows Perception Service Elevation of Privilege Vulnerability |