CWE-367
696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (696)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 56Aqt1000 Firmware Qca6390 FirmwareQca6391 Firmware+53 moreJun 17, 2026 Sep 16, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
1Qualcomm 56Aqt1000 Firmware Qca6390 FirmwareQca6391 Firmware+53 moreJun 17, 2026 Sep 16, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach or detach IRQs from virtual interrupt sources in Snapdragon Compute, Snapdragon Connectivity, Snapdr...Show more |
1Dell 399Alienware M15 R6 Firmware Chengming 3980 FirmwareChengming 3988 Firmware+396 moreJun 17, 2026 Sep 6, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM. |
A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacker with CAP_NET_ADMIN privilege to leak ke...Show more |
3Fedoraproject RedhatRpm3Enterprise Linux FedoraRpmJun 17, 2026 Aug 25, 2022 N/A· v4 6.4 MEDIUM· v3 N/A· v2 A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI comman...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI comman...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI comman...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI comman...Show more |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target h...Show more |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execute low-privileged code on the target syste...Show more |
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations. |
Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process. |
1Qualcomm 38Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+35 moreJun 17, 2026 Jun 14, 2022 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile |
1Qualcomm 56Aqt1000 Firmware Qca6390 FirmwareQca6391 Firmware+53 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
1Qualcomm 3Mdm9206 Firmware Qca9367 FirmwareQca9377 FirmwareJun 17, 2026 Jun 14, 2022 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT |
1Qualcomm 64Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+61 moreJun 17, 2026 Jun 14, 2022 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industr...Show more |
1Qualcomm 64Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+61 moreJun 17, 2026 Jun 14, 2022 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IO...Show more |
1Qualcomm 95Apq8009w Firmware Apq8017 FirmwareApq8096au Firmware+92 moreJun 17, 2026 Jun 14, 2022 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IO...Show more |
Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieve...Show more |