CWE-367
696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (696)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hp 387Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+384 moreJun 17, 2026 Jun 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. |
1Hp 387Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+384 moreJun 17, 2026 Jun 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. |
Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours. |
1Amd 55Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+52 moreJun 17, 2026 May 9, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event pot...Show more |
1Amd 98Epyc 7001 Firmware Epyc 7002 FirmwareEpyc 7232p Firmware+95 moreJun 17, 2026 May 9, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption and information disclosure.
|
Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerS...Show more |
3Debian LinuxNetapp8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Apr 24, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabil...Show more |
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the restore process leading to arbitrary file creation. The issue was fixed with Avast and AVG Antivirus vers...Show more |
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quarantine process, leading to arbitrary file/directory deletion. The issue was fixed with Avast and AVG...Show more |
1Qualcomm 42Ar8035 Firmware Qca6391 FirmwareQca6595au Firmware+39 moreJun 17, 2026 Apr 13, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message. |
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition. |
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientW...Show more |
1Tesla 4Model 3 Firmware Model S FirmwareModel X Firmware+1 moreJun 17, 2026 Mar 29, 2023 N/A· v4 6.4 MEDIUM· v3 N/A· v2 This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ice_updater update mech...Show more |
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication...Show more |
2Podman Project Redhat2Enterprise Linux PodmanJun 17, 2026 Mar 27, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files...Show more |
Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installatio...Show more |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Mar 14, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 Windows Graphics Component Elevation of Privilege Vulnerability |
1Microsoft 1Malware Protection Engine Jun 17, 2026 Mar 14, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Microsoft Defender Elevation of Privilege Vulnerability |
1Qualcomm 140Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+137 moreJun 17, 2026 Mar 10, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone. |
In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...Show more |