VYPR

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

BaseIncompleteLikelihood: Medium

Description

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-27 · CAPEC-29

CVEs mapped to this weakness (740)

page 1 of 37
  • CVE-2025-22224CriKEVMar 4, 2025
    risk 0.73cvss 9.3epss 0.02

    VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process…

  • CVE-2023-35311HigKEVJul 11, 2023
    risk 0.70cvss 8.8epss 0.16

    Microsoft Outlook Security Feature Bypass Vulnerability

  • CVE-2024-30088HigKEVJun 11, 2024
    risk 0.69cvss 7.0epss 0.68

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2025-34027CriMay 21, 2025
    risk 0.68cvss epss 0.37

    The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU)…

  • CVE-2025-64180CriNov 7, 2025
    risk 0.65cvss 10.0epss 0.00

    Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network resources. The flaw lies in the fundamental design of the DNS validation mechanism. A Time-of-Check…

  • CVE-2026-63297CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.00

    An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction…

  • CVE-2026-37531CriMay 1, 2026
    risk 0.64cvss 9.8epss 0.01

    AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP entry names but does not check for dot…

  • CVE-2025-13032CriNov 11, 2025
    risk 0.64cvss 9.9epss 0.00

    Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

  • CVE-2024-41787CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.01

    IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.

  • CVE-2024-41779CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.

  • CVE-2024-0132CriSep 26, 2024
    risk 0.64cvss 9.0epss 0.38

    NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A…

  • CVE-2024-27114CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.01

    A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to…

  • CVE-2019-7249CriJan 31, 2019
    risk 0.64cvss 9.8epss 0.03

    In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.

  • CVE-2023-38146HigSep 12, 2023
    risk 0.63cvss 8.8epss 0.39

    Windows Themes Remote Code Execution Vulnerability

  • CVE-2024-50379CriDec 17, 2024
    risk 0.60cvss 9.8epss 0.44

    Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1…

  • CVE-2022-33257CriMar 10, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.

  • CVE-2021-35090CriJun 14, 2022
    risk 0.60cvss 9.3epss 0.00

    Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2026-20677CriFeb 11, 2026
    risk 0.59cvss 9.0epss 0.00

    A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.

  • CVE-2022-36980HigMar 29, 2023
    risk 0.59cvss 8.1epss 0.83

    This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within…

  • CVE-2021-35082CriJun 14, 2022
    risk 0.59cvss 9.1epss 0.00

    Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT