CWE-367
696 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (696)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Nov 14, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows Server 2016, Win...Show more |
1Mcafee 2Endpoint Security For Linux Threat Prevention Endpoint Security Linux Threat PreventionJun 17, 2026 Sep 18, 2018 N/A· v4 5.3 MEDIUM· v3 3.3 LOW· v2 An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specif...Show more |
1Microsoft 2Windows 10 Windows Server 2016Jun 17, 2026 Sep 13, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. |
procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to d...Show more |
1Microsoft 2Windows 10 Windows Server 2016Nov 21, 2024 Apr 12, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. |
1Microsoft 3Windows 10 Windows ServerWindows Server 2016May 13, 2026 Nov 15, 2017 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka "D...Show more |
fts.c in coreutils 8.4 allows local users to delete arbitrary files. |
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34621073. |
An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibi...Show more |
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could...Show more |
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could...Show more |
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1748. |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaApr 29, 2026 Oct 9, 2013 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 dxgkrnl.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel S...Show more |
3Canonical DebianGnu3Cpio Debian LinuxUbuntu LinuxApr 16, 2026 May 2, 2005 N/A· v4 4.7 MEDIUM· v3 3.7 LOW· v2 Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompre...Show more |
6Avaya DebianHp+3 more6Converged Communications Server Debian LinuxHp Ux+3 moreApr 16, 2026 Jul 27, 2004 N/A· v4 N/A· v3 5.1 MEDIUM· v2 The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_l...Show more |
1Microsoft 5Windows 2000 Windows 98Windows Nt+2 moreApr 16, 2026 Nov 17, 2003 N/A· v4 N/A· v3 5.1 MEDIUM· v2 A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RP...Show more |