← Back
CWE-367

788 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.

JSON object

Loading...

CVEs (788)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Parallels
1Parallels Access
Jun 17, 2026
Jul 18, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target h...Show more
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels service. By creating a symbolic link, an attacker can abuse the service to execute a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-16134.Show less
1Parallels
1Parallels Desktop
Jun 17, 2026
Jul 15, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execute low-privileged code on the target syste...Show more
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Parallels Service. By creating a symbolic link, an attacker can abuse the service to execute a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-13932.Show less
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.
1Automox
1Automox
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process.
1Qualcomm
38Ar8035 Firmware
Qca6390 FirmwareQca6391 Firmware+35 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile
1Qualcomm
56Aqt1000 Firmware
Qca6390 FirmwareQca6391 Firmware+53 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
1Qualcomm
3Mdm9206 Firmware
Qca9367 FirmwareQca9377 Firmware
Jun 17, 2026
Jun 14, 2022
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT
1Qualcomm
64Ar8035 Firmware
Qca6390 FirmwareQca6391 Firmware+61 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industr...Show more
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon MobileShow less
1Qualcomm
64Ar8035 Firmware
Qca6390 FirmwareQca6391 Firmware+61 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IO...Show more
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon MobileShow less
1Qualcomm
95Apq8009w Firmware
Apq8017 FirmwareApq8096au Firmware+92 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IO...Show more
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon WearablesShow less
1Quickheal
1Total Security
Jun 17, 2026
May 23, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieve...Show more
Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as malicious and when the action of quarantining or cleaning is performed, and using the time to replace the malicious file by a symlink.Show less
1Lenovo
1System Interface Foundation
Jun 17, 2026
May 18, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3that could allow a local attacker to elevate privilege...Show more
A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3that could allow a local attacker to elevate privileges.Show less
1Lenovo
1System Interface Foundation
Jun 17, 2026
May 18, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMCont...Show more
A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMController child process' named pipe.Show less
1Amd
44Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+41 more
Jun 17, 2026
May 11, 2022
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.
1Gruntjs
1Grunt
Jun 17, 2026
May 10, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which ca...Show more
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.Show less
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch...Show more
In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS06399901.Show less
1Foscam
2R2c Application Firmware
R2c System Firmware
Jun 17, 2026
Apr 21, 2022
N/A· v4
6.6 MEDIUM· v3
8.5 HIGH· v2
Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permission...Show more
Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permissions to execute arbitrary remote code via a malicious firmware patch. The impact of this vulnerability is that the remote attacker could gain full remote access to the IP camera and the underlying Linux system with root permissions. With root access to the camera's Linux OS, an attacker could effectively change the code that is running, add backdoor access, or invade the privacy of the user by accessing the live camera stream.Show less
1Amazon
1Aws Client Vpn
Jun 17, 2026
Apr 14, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows parameters outside of the AWS VPN Client allow list to be injected into...Show more
An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows parameters outside of the AWS VPN Client allow list to be injected into the configuration file prior to the AWS VPN Client service (running as SYSTEM) processing the file. Dangerous arguments can be injected by a low-level user such as log, which allows an arbitrary destination to be specified for writing log files. This leads to an arbitrary file write as SYSTEM with partial control over the files content. This can be abused to cause an elevation of privilege or denial of service.Show less
1Logitech
1Sync
Jun 17, 2026
Apr 12, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escalate the permission to the system user.
1Dell
1Emc Powerscale Onefs
Jun 17, 2026
Apr 12, 2022
N/A· v4
3.6 LOW· v3
3.3 LOW· v2
Dell PowerScale OneFS, versions 8.2.2-9.3.x, contain a time-of-check-to-time-of-use vulnerability. A local user with access to the filesystem could potentially exploit this vulnerability, leading to data loss.