← Back
CWE-367

696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.

JSON object

Loading...

CVEs (696)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freebsd
1Freebsd
Jun 17, 2026
Feb 15, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memory corruption. On systems configured to...Show more
The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memory corruption. On systems configured to include netmap in their devfs_ruleset, a privileged process running in a jail can affect the host environment.Show less
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Feb 13, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Feb 13, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Security Feature Bypass Vulnerability
1Qualcomm
48Ar8035 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+45 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.
1Apple
5Ipados
Iphone OsMacos+2 more
Jun 17, 2026
Jan 9, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointe...Show more
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.Show less
1Buildkite
1Elastic Ci Stack
Jun 17, 2026
Dec 22, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to bypass a symbolic link check for the PIPELINE_PATH variable i...Show more
A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to bypass a symbolic link check for the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script.Show less
1Github
1Enterprise Server
Jun 17, 2026
Dec 21, 2023
N/A· v4
4.0 MEDIUM· v3
N/A· v2
A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixe...Show more
A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1. Show less
1Github
1Enterprise Server
Jun 17, 2026
Dec 21, 2023
N/A· v4
2.0 LOW· v3
N/A· v2
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerabil...Show more
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1. Show less
1Github
1Enterprise Server
Jun 17, 2026
Dec 21, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user. This vulnerability affected all versions...Show more
A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12, 3.9.7, 3.10.4, and 3.11.1. Show less
1Quicoto
1Thumbs Rating
Jun 17, 2026
Dec 19, 2023
N/A· v4
3.7 LOW· v3
N/A· v2
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0.
1Insyde
1Insydeh2o
Jun 17, 2026
Dec 16, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel 5.5 before version 05.52.13 allows an at...Show more
TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel 5.5 before version 05.52.13 allows an attacker to alter data and code used by the remainder of the boot process.Show less
1Samsung
7Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1380 Firmware+4 more
Jun 17, 2026
Dec 13, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.
1Yet Another Stars Rating Project
1Yet Another Stars Rating
Jun 17, 2026
Nov 30, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: fro...Show more
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8.Show less
1Amd
93Amd 3015ce Firmware
Amd 3015e FirmwareAthlon Gold 3150g Firmware+90 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
1Avas!t
1Avg Antivirus
Jun 17, 2026
Nov 8, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain...Show more
A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8. Show less
1Foodcoopshop
1Foodcoopshop
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side request forgery. In the Network module, a manufacturer account can use the `/...Show more
FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side request forgery. In the Network module, a manufacturer account can use the `/api/updateProducts.json` endpoint to make the server send a request to an arbitrary host. This means that the server can be used as a proxy into the internal network where the server is. Furthermore, the checks on a valid image are not adequate, leading to a time of check time of use issue. For example, by using a custom server that returns 200 on HEAD requests, then return a valid image on first GET request and then a 302 redirect to final target on second GET request, the server will copy whatever file is at the redirect destination, making this a full SSRF. Version 3.6.1 fixes this vulnerability.Show less
1Lenovo
3Hardware Scan Addin
Hardware Scan PluginSystem Update Plugin
Jun 17, 2026
Oct 27, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions.
1Lenovo
3Hardware Scan Addin
Hardware Scan PluginSystem Update Plugin
Jun 17, 2026
Oct 27, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.
1Lenovo
3Hardware Scan Addin
Hardware Scan PluginSystem Update Plugin
Jun 17, 2026
Oct 27, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files.
1Ivanti
1Secure Access Client
Jun 17, 2026
Oct 25, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized ele...Show more
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.Show less