← Back
CWE-367

696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.

JSON object

Loading...

CVEs (696)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Qemu
2Debian Linux
Qemu
Jun 17, 2026
May 13, 2021
N/A· v4
7.5 HIGH· v3
6.9 MEDIUM· v2
A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the...Show more
A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity as well as system availability.Show less
1Mcafee
1Endpoint Security For Linux Threat Prevention
Jun 17, 2026
May 12, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalatio...Show more
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose of executing arbitrary code through insecure use of predictable temporary file locations.Show less
1Dell
1Idrac9 Firmware
Jun 17, 2026
Apr 30, 2021
N/A· v4
7.1 HIGH· v3
4.6 MEDIUM· v2
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privil...Show more
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.Show less
1Parallels
1Parallels Desktop
Jun 17, 2026
Apr 29, 2021
N/A· v4
5.6 MEDIUM· v3
1.9 LOW· v2
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute low-privileged code on the tar...Show more
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Open Tools Gate component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-13082.Show less
1Parallels
1Parallels Desktop
Jun 17, 2026
Apr 29, 2021
N/A· v4
7.5 HIGH· v3
4.4 MEDIUM· v2
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An attacker must first obtain the ability to execute high-privileged code on the target guest...Show more
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the e1000e virtual device. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-12527.Show less
1Qualcomm
180Aqt1000 Firmware
Fsm10055 FirmwarePm3003a Firmware+177 more
Jun 17, 2026
Mar 17, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes a physical address to user land in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn...Show more
Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes a physical address to user land in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon MobileShow less
1Qualcomm
131Aqt1000 Firmware
Ar8035 FirmwarePm4125 Firmware+128 more
Jun 17, 2026
Mar 17, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, S...Show more
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and NetworkingShow less
1Mozilla
1Firefox
Jun 17, 2026
Feb 26, 2021
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories. Note: This issue is only affected Firefox for Android....Show more
Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories. Note: This issue is only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.Show less
2Debian
Firejail Project
2Debian Linux
Firejail
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
3Cisco
MadshiMorphisec
3Advanced Malware Protection
MadcodehookUnified Threat Prevention Platform
Jun 17, 2026
Jan 30, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.
1Jenkins
1Jenkins
Jun 17, 2026
Jan 26, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
1Crayon Project
1Crayon
Jun 17, 2026
Dec 31, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the crayon crate through 2020-08-31 for Rust. A TOCTOU issue has a resultant memory safety violation via HandleLike.
1Pengutronix
1Rauc
Jun 17, 2026
Dec 21, 2020
N/A· v4
6.6 MEDIUM· v3
7.1 HIGH· v2
The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for in...Show more
The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device.Show less
1Medtronic
1Mycarelink Smart Model 25000 Firmware
Jun 17, 2026
Dec 14, 2020
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited,...Show more
Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited, an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.Show less
1Amd
1Trusted Platform Modules Reference
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be c...Show more
The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be compromised. AMD believes that the attack requires physical access of the device because the power must be repeatedly turned on and off. This potential attack may be used to change confidential information, alter executables signed by key material in the TPM, or create a denial of service of the device.Show less
1Lenovo
1Notebook Firmware
Jun 17, 2026
Nov 11, 2020
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader+1 more
Jun 17, 2026
Nov 5, 2020
N/A· v4
7.7 HIGH· v3
5.1 MEDIUM· v2
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a time-of-check time-of-use (TOCTOU) race condition vulnerability that coul...Show more
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a time-of-check time-of-use (TOCTOU) race condition vulnerability that could result in local privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Trendmicro
1Antivirus+
Jun 17, 2026
Oct 30, 2020
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash.\n\n\r\nA...Show more
Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash.\n\n\r\nAn attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.Show less
1Apple
1Mac Os X
Jun 17, 2026
Oct 22, 2020
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to load unsigned kernel extensions.
1Apple
1Mac Os X
Jun 17, 2026
Oct 22, 2020
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A malicious application may be able to execute arbitrary code with system privileges.