← Back
CWE-367

696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.

JSON object

Loading...

CVEs (696)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
387Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware
Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+384 more
Jun 17, 2026
Jun 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
1Hp
387Dragonfly Folio 13.5 Inch G3 2 In 1 Notebook Pc Firmware
Elite Dragonfly 13.5 Inch G3 Notebook Pc FirmwareElite Dragonfly Firmware+384 more
Jun 17, 2026
Jun 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
1Getvideostream
1Videostream
Jun 17, 2026
May 17, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours.
1Amd
55Athlon Gold 3150g Firmware
Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+52 more
Jun 17, 2026
May 9, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event pot...Show more
Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service. Show less
1Amd
98Epyc 7001 Firmware
Epyc 7002 FirmwareEpyc 7232p Firmware+95 more
Jun 17, 2026
May 9, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
1Docker
1Desktop
Jun 17, 2026
Apr 27, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerS...Show more
Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink vulnerability in ..\dataRoot\network\files\local-kv.db because of a TOCTOU race condition.Show less
3Debian
LinuxNetapp
8Debian Linux
H300s FirmwareH410c Firmware+5 more
Jun 17, 2026
Apr 24, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabil...Show more
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.Show less
2Avas!t
Avg
2Anti Virus
Antivirus
Jun 17, 2026
Apr 19, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the restore process leading to arbitrary file creation. The issue was fixed with Avast and AVG Antivirus vers...Show more
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the restore process leading to arbitrary file creation. The issue was fixed with Avast and AVG Antivirus version 22.11Show less
2Avas!t
Avg
2Anti Virus
Antivirus
Jun 17, 2026
Apr 19, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quarantine process, leading to arbitrary file/directory deletion. The issue was fixed with Avast and AVG...Show more
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quarantine process, leading to arbitrary file/directory deletion. The issue was fixed with Avast and AVG Antivirus version 22.11 and virus definitions from 14 February 2023 or later. Show less
1Qualcomm
42Ar8035 Firmware
Qca6391 FirmwareQca6595au Firmware+39 more
Jun 17, 2026
Apr 13, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.
1Paloaltonetworks
1Globalprotect
Jun 17, 2026
Apr 12, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition.
1Fortinet
1Forticlient
Jun 17, 2026
Apr 11, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientW...Show more
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.Show less
1Tesla
4Model 3 Firmware
Model S FirmwareModel X Firmware+1 more
Jun 17, 2026
Mar 29, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ice_updater update mech...Show more
This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ice_updater update mechanism. The issue results from the lack of proper validation of user-supplied firmware. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-17463.Show less
1Ivanti
1Avalanche
Jun 17, 2026
Mar 29, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication...Show more
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the EnterpriseServer service. The issue results from the lack of proper locking when performing operations during authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15528.Show less
2Podman Project
Redhat
2Enterprise Linux
Podman
Jun 17, 2026
Mar 27, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files...Show more
A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.Show less
1Zoom
1Meetings
Jun 17, 2026
Mar 16, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installatio...Show more
Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to the SYSTEM user.Show less
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Mar 14, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Graphics Component Elevation of Privilege Vulnerability
1Microsoft
1Malware Protection Engine
Jun 17, 2026
Mar 14, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Microsoft Defender Elevation of Privilege Vulnerability
1Qualcomm
140Aqt1000 Firmware
Ar8031 FirmwareAr8035 Firmware+137 more
Jun 17, 2026
Mar 10, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
2Google
Yoctoproject
2Android
Yocto
Jun 17, 2026
Mar 7, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...Show more
In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559778; Issue ID: ALPS07559778.Show less