CWE-367
696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (696)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Paloaltonetworks 1Globalprotect Jun 17, 2026 Jun 10, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalPro...Show more |
1Qualcomm 18Apq8009 Firmware Apq8053 FirmwareMsm8909w Firmware+15 moreJun 17, 2026 Jun 2, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ805...Show more |
1Vmware 3Fusion Horizon ClientRemote ConsoleJun 17, 2026 May 29, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Apr 22, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this can be exploited betwee...Show more |
1Opcfoundation 1Unified Architecture .net Standard Jun 17, 2026 Apr 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. T...Show more |
A privilege escalation vulnerability in Juniper Networks Junos OS devices configured with dual Routing Engines (RE), Virtual Chassis (VC) or high-availability cluster may allow a local authenticated low-privileged user w...Show more |
1Opensuse 2Leap Texlive FilesystemJun 17, 2026 Apr 2, 2020 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP...Show more |
A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE L...Show more |
Creative Cloud Desktop Application versions 5.0 and earlier have a time-of-check to time-of-use (toctou) race condition vulnerability. Successful exploitation could lead to arbitrary file deletion. |
An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code executi...Show more |
1Parallels 1Parallels Desktop Jun 17, 2026 Mar 23, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest...Show more |
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cach...Show more |
3Canonical FedoraprojectOpensmtpd3Fedora OpensmtpdUbuntu LinuxJun 17, 2026 Feb 25, 2020 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in...Show more |
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests. |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories. |
2Apple Broadcom9Bcm43012 Firmware Bcm43013 FirmwareBcm4356 Firmware+6 moreJun 17, 2026 Feb 5, 2020 N/A· v4 3.1 LOW· v3 2.9 LOW· v2 An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryptio...Show more |
An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware signature checks atomically, leading to...Show more |
In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege with no additional execution privileges n...Show more |
1Bullguard 1Premium Protection Jun 17, 2026 Dec 26, 2019 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link attack, allowing privileged files to be deleted. |
In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain can gain privileges. |