CWE-367
788 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (788)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code executi...Show more |
1Parallels 1Parallels Desktop Jun 17, 2026 Mar 23, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest...Show more |
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cach...Show more |
3Canonical FedoraprojectOpensmtpd3Fedora OpensmtpdUbuntu LinuxJun 17, 2026 Feb 25, 2020 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in...Show more |
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests. |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories. |
2Apple Broadcom9Bcm43012 Firmware Bcm43013 FirmwareBcm4356 Firmware+6 moreJun 17, 2026 Feb 5, 2020 N/A· v4 3.1 LOW· v3 2.9 LOW· v2 An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryptio...Show more |
An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware signature checks atomically, leading to...Show more |
In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege with no additional execution privileges n...Show more |
1Bullguard 1Premium Protection Jun 17, 2026 Dec 26, 2019 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link attack, allowing privileged files to be deleted. |
In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain can gain privileges. |
1Qualcomm 41Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+38 moreJun 17, 2026 Dec 12, 2019 N/A· v4 8.1 HIGH· v3 4.4 MEDIUM· v2 Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapd...Show more |
3Debian FedoraprojectRedhat4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Dec 3, 2019 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees |
3Fedoraproject Libuser ProjectRedhat3Enterprise Linux FedoraLibuserNov 21, 2024 Nov 25, 2019 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 22, 2019 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files |
1Qualcomm 36Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+33 moreJun 17, 2026 Nov 21, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out of bound access in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consum...Show more |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreJun 17, 2026 Nov 12, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'. |
The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted. |
Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loo...Show more |
Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubuntu5 contained a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml file, which allow...Show more |