VYPR

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

BaseIncompleteLikelihood: Medium

Description

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-27 · CAPEC-29

CVEs mapped to this weakness (741)

page 25 of 38
  • CVE-2025-49558MedAug 12, 2025
    risk 0.38cvss 5.9epss 0.00

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability by…

  • CVE-2024-47494MedOct 11, 2024
    risk 0.38cvss 5.9epss 0.00

    A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during telemetry polling,…

  • CVE-2023-6803MedDec 21, 2023
    risk 0.38cvss 5.8epss 0.00

    A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub Enterprise Server since 3.8 and was fixed in version 3.8.12, 3.9.7, 3.10.4, and 3.11.1.

  • CVE-2021-46792MedMay 9, 2023
    risk 0.38cvss 5.9epss 0.00

    Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service.

  • CVE-2023-23520MedFeb 27, 2023
    risk 0.38cvss 5.9epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may be able to read arbitrary files as root.

  • CVE-2021-46853MedNov 3, 2022
    risk 0.38cvss 5.9epss 0.01

    Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.

  • CVE-2022-22225MedOct 18, 2022
    risk 0.38cvss 5.9epss 0.00

    A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker with an established BGP session to cause a Denial of Service (DoS). In a BGP multipath…

  • CVE-2022-22220MedOct 18, 2022
    risk 0.38cvss 5.9epss 0.00

    A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS, Junos OS Evolved allows a network-based unauthenticated attacker to cause a Denial of Service (DoS). When a BGP flow route with redirect IP extended…

  • CVE-2021-21539MedApr 30, 2021
    risk 0.38cvss 5.9epss 0.01

    Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously…

  • CVE-2020-3981MedOct 20, 2020
    risk 0.38cvss 5.8epss 0.01

    VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious…

  • CVE-2020-3808MedMar 25, 2020
    risk 0.38cvss 5.9epss 0.01

    Creative Cloud Desktop Application versions 5.0 and earlier have a time-of-check to time-of-use (toctou) race condition vulnerability. Successful exploitation could lead to arbitrary file deletion.

  • CVE-2020-8890MedFeb 12, 2020
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.

  • CVE-2019-20000MedDec 26, 2019
    risk 0.38cvss 5.9epss 0.01

    The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link attack, allowing privileged files to be deleted.

  • CVE-2019-18644MedOct 31, 2019
    risk 0.38cvss 5.9epss 0.01

    The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted.

  • CVE-2017-11830MedNov 15, 2017
    risk 0.38cvss 5.3epss 0.03

    Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka "Device Guard Security Feature Bypass Vulnerability".

  • CVE-2026-5303MedAug 11, 2026
    risk 0.37cvss 5.7epss 0.00

    The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an…

  • CVE-2026-41360MedApr 23, 2026
    risk 0.37cvss 6.7epss 0.00

    OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution without invalidating the approval plan, allowing execution…

  • CVE-2026-4878MedApr 9, 2026
    risk 0.37cvss 6.7epss 0.00

    A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an…

  • CVE-2023-20135MedSep 13, 2023
    risk 0.37cvss 5.7epss 0.00

    A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition when an install…

  • CVE-2023-0778MedMar 27, 2023
    risk 0.37cvss 6.8epss 0.01

    A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.