CWE-367
788 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (788)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Cisco MadshiMorphisec3Advanced Malware Protection MadcodehookUnified Threat Prevention PlatformJun 17, 2026 Jan 30, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions. |
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition. |
An issue was discovered in the crayon crate through 2020-08-31 for Rust. A TOCTOU issue has a resultant memory safety violation via HandleLike. |
The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for in...Show more |
1Medtronic 1Mycarelink Smart Model 25000 Firmware Jun 17, 2026 Dec 14, 2020 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited,...Show more |
1Amd 1Trusted Platform Modules Reference Jun 17, 2026 Nov 12, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be c...Show more |
A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution. |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Nov 5, 2020 N/A· v4 7.7 HIGH· v3 5.1 MEDIUM· v2 Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a time-of-check time-of-use (TOCTOU) race condition vulnerability that coul...Show more |
Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash.\n\n\r\nA...Show more |
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to load unsigned kernel extensions. |
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A malicious application may be able to execute arbitrary code with system privileges. |
1Vmware 5Cloud Foundation EsxiFusion+2 moreJun 17, 2026 Oct 20, 2020 N/A· v4 7.7 HIGH· v3 4.9 MEDIUM· v2 VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a ti...Show more |
1Vmware 4Cloud Foundation EsxiFusion+1 moreJun 17, 2026 Oct 20, 2020 N/A· v4 5.8 MEDIUM· v3 3.5 LOW· v2 VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a tim...Show more |
1Lenovo 18Bladecenter Hs23 Firmware Bladecenter Hs23e FirmwareCompute Node X440 Firmware+15 moreJun 17, 2026 Oct 14, 2020 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not af...Show more |
3Canonical DpdkOpensuse3Data Plane Development Kit LeapUbuntu LinuxJun 17, 2026 Sep 30, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker...Show more |
In SurfaceFlinger, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pro...Show more |
A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege. |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 9, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead...Show more |
1Qualcomm 44Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+41 moreJun 17, 2026 Sep 8, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 u'Non-secure memory is touched multiple times during TrustZone\u2019s execution and can lead to privilege escalation or memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consu...Show more |
1Qualcomm 25Ipq6018 Firmware Kamorta FirmwareMdm9205 Firmware+22 moreJun 17, 2026 Sep 8, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition and lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapd...Show more |