VYPR

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

BaseIncompleteLikelihood: Medium

Description

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-27 · CAPEC-29

CVEs mapped to this weakness (741)

page 19 of 38
  • CVE-2025-13818MedFeb 6, 2026
    risk 0.44cvss 6.7epss 0.00

    Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent

  • CVE-2025-67124MedJan 23, 2026
    risk 0.44cvss 6.8epss 0.00

    A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the…

  • CVE-2025-47344MedJan 7, 2026
    risk 0.44cvss 6.7epss 0.00

    Memory corruption while handling sensor utility operations.

  • CVE-2025-47332MedJan 7, 2026
    risk 0.44cvss 6.7epss 0.00

    Memory corruption while processing a config call from userspace.

  • CVE-2025-9810MedSep 1, 2025
    risk 0.44cvss 6.8epss 0.00

    TOCTOU  in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path and subsequent chmod() on the same path.

  • CVE-2025-48818MedJul 8, 2025
    risk 0.44cvss 6.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-48001MedJul 8, 2025
    risk 0.44cvss 6.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-22394MedJan 15, 2025
    risk 0.44cvss 6.7epss 0.00

    Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code execution and possibly privilege escalation.

  • CVE-2024-39826MedJul 15, 2024
    risk 0.44cvss 6.8epss 0.00

    Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access.

  • CVE-2024-26974HigMay 1, 2024
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: crypto: qat - resolve race condition during AER recovery During the PCI AER system's error recovery process, the kernel driver may encounter a race condition with freeing the reset_data structure's memory. If…

  • CVE-2023-34046MedOct 20, 2023
    risk 0.44cvss 6.7epss 0.00

    VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious…

  • CVE-2022-25716MedJan 9, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Multimedia Framework due to unsafe access to the data members

  • CVE-2021-0897MedDec 17, 2021
    risk 0.44cvss 6.7epss 0.00

    In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05670549.

  • CVE-2020-8873MedMar 23, 2020
    risk 0.44cvss 6.7epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific…

  • CVE-2020-0003MedJan 8, 2020
    risk 0.44cvss 6.7epss 0.00

    In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.…

  • CVE-2019-5519MedApr 1, 2019
    risk 0.44cvss 6.8epss 0.01

    VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual…

  • CVE-2026-44113HigMay 6, 2026
    risk 0.43cvss 7.7epss 0.00

    OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions…

  • CVE-2026-26017HigMar 6, 2026
    risk 0.43cvss 7.7epss 0.00

    CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a…

  • CVE-2026-27189MedFeb 21, 2026
    risk 0.43cvss 6.6epss 0.00

    OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below, use non-atomic and insufficiently synchronized local JSON persistence flows, potentially causing concurrent operations to lose updates or…

  • CVE-2025-58131MedSep 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may allow an authenticated user to conduct a disclosure of information via network access.