CWE-367
788 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
CVEs (788)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could...Show more |
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could...Show more |
3Libuser Project OpensuseRedhat4Enterprise Linux LibuserLibuser+1 moreAug 27, 2026 Aug 11, 2015 N/A· v4 5.1 MEDIUM· v3 7.2 HIGH· v2 libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) b...Show more |
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1748. |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaApr 29, 2026 Oct 9, 2013 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 dxgkrnl.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel S...Show more |
3Canonical DebianGnu3Cpio Debian LinuxUbuntu LinuxApr 16, 2026 May 2, 2005 N/A· v4 4.7 MEDIUM· v3 3.7 LOW· v2 Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompre...Show more |
6Avaya DebianHp+3 more6Converged Communications Server Debian LinuxHp Ux+3 moreApr 16, 2026 Jul 27, 2004 N/A· v4 N/A· v3 5.1 MEDIUM· v2 The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_l...Show more |
1Microsoft 5Windows 2000 Windows 98Windows Nt+2 moreApr 16, 2026 Nov 17, 2003 N/A· v4 N/A· v3 5.1 MEDIUM· v2 A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RP...Show more |