CWE-367
788 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (788)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target h...Show more |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execute low-privileged code on the target syste...Show more |
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations. |
Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process. |
1Qualcomm 38Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+35 moreJun 17, 2026 Jun 14, 2022 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile |
1Qualcomm 56Aqt1000 Firmware Qca6390 FirmwareQca6391 Firmware+53 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
1Qualcomm 3Mdm9206 Firmware Qca9367 FirmwareQca9377 FirmwareJun 17, 2026 Jun 14, 2022 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT |
1Qualcomm 64Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+61 moreJun 17, 2026 Jun 14, 2022 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industr...Show more |
1Qualcomm 64Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+61 moreJun 17, 2026 Jun 14, 2022 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IO...Show more |
1Qualcomm 95Apq8009w Firmware Apq8017 FirmwareApq8096au Firmware+92 moreJun 17, 2026 Jun 14, 2022 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IO...Show more |
Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieve...Show more |
1Lenovo 1System Interface Foundation Jun 17, 2026 May 18, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3that could allow a local attacker to elevate privilege...Show more |
1Lenovo 1System Interface Foundation Jun 17, 2026 May 18, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMCont...Show more |
1Amd 44Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+41 moreJun 17, 2026 May 11, 2022 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service. |
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which ca...Show more |
In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch...Show more |
1Foscam 2R2c Application Firmware R2c System FirmwareJun 17, 2026 Apr 21, 2022 N/A· v4 6.6 MEDIUM· v3 8.5 HIGH· v2 Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permission...Show more |
An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows parameters outside of the AWS VPN Client allow list to be injected into...Show more |
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user. |
Dell PowerScale OneFS, versions 8.2.2-9.3.x, contain a time-of-check-to-time-of-use vulnerability. A local user with access to the filesystem could potentially exploit this vulnerability, leading to data loss. |