CWE-367: CWE-367
Yearly Trend
Top Affected Vendors
All CWE-367 CVEs (175)
A time-of-check time-of-use race condition vulnerability in Microsoft Defender for Linux allows a local authenticated attacker to cause a denial of se...
Oct 14, 2025A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Microsoft Graphics Component allows authenticated attackers to elevate privileges...
Oct 14, 2025A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Windows TCP/IP stack allows authenticated local attackers to elevate privileges b...
Sep 9, 2025A time-of-check time-of-use race condition vulnerability in Windows NTFS allows local attackers to read unauthorized files or memory contents. This af...
Aug 12, 2025A race condition vulnerability in NVIDIA .run installers for Linux and Solaris allows local attackers to escalate privileges. This affects systems whe...
Aug 2, 2025This vulnerability in Microsoft AutoUpdate (MAU) allows attackers to gain elevated privileges on affected systems. It affects macOS devices running Mi...
Feb 11, 2025A race condition vulnerability in the Linux kernel's iwlegacy WiFi driver allows stale interrupts to trigger during system resume from hibernation, ca...
Nov 9, 2024This CVE describes a local privilege escalation vulnerability in Elefant Update Service where an attacker with local access can exploit a race conditi...
Nov 8, 2024This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Adobe Acrobat Reader that could allow local attackers to escal...
Aug 14, 2024This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution...
Aug 14, 2024This vulnerability allows an authenticated attacker to elevate privileges on Windows systems by exploiting the Windows Perception Service. It affects ...
Jun 11, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's Direct Rendering Manager (DRM) subsystem. Attackers could potentially exploit ...
May 21, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's Intel QAT crypto driver during PCI AER error recovery. A race condition occurs...
May 1, 2024This CVE describes a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in openEuler iSulad container runtime. It allows attackers to exp...
Mar 25, 2024This vulnerability allows attackers to elevate privileges on Windows systems by exploiting the Print Spooler service. Attackers could gain SYSTEM-leve...
Mar 12, 2024This vulnerability allows an attacker with arbitrary read/write capability to bypass Pointer Authentication security mechanisms on Apple devices. It a...
Jan 9, 2024CVE-2023-38041 is a privilege escalation vulnerability in Ivanti software where authenticated users can exploit a Time-of-Check to Time-of-Use (TOCTOU...
Oct 25, 2023This vulnerability in N-able Take Control Agent allows attackers to delete arbitrary files through a time-of-check to time-of-use (TOCTOU) race condit...
Sep 11, 2023This vulnerability in Windows Projected File System allows attackers to elevate privileges on affected systems. It enables local authenticated users t...
Aug 8, 2023A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in AMI UEFI Firmware on certain HP PC products could allow attackers to execute arbitrary code d...
Jun 30, 2023This CVE describes a Time-of-Check Time-of-Use (TOCTOU) vulnerability in Trend Micro Apex One and Apex One as a Service agents that allows local attac...
Jun 26, 2023This vulnerability allows a local unprivileged Windows user to exploit a race condition in the Netskope client service to gain SYSTEM-level privileges...
Jun 15, 2023This CVE describes vulnerabilities in the system BIOS of certain HP PC products that could allow attackers to execute arbitrary code, escalate privile...
Jun 14, 2023CVE-2023-24861 is a privilege escalation vulnerability in the Windows Graphics Component that allows authenticated attackers to gain SYSTEM-level priv...
Mar 14, 2023This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on a shared buffer between SMM and non-SMM code, creating a TOCTOU race condition. ...
Feb 15, 2023This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on the PnpSmm shared buffer, creating TOCTOU race conditions that can corrupt SMRAM...
Feb 15, 2023This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on the HddPassword shared buffer, creating TOCTOU race conditions that can corrupt ...
Feb 15, 2023This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on the SdHostDriver buffer, creating TOCTOU race conditions that can corrupt SMRAM ...
Feb 15, 2023This vulnerability in InsydeH2O firmware allows attackers with local access to potentially escalate privileges or corrupt data by exploiting a time-of...
Feb 15, 2023This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on a shared buffer between SMM and non-SMM code, creating a TOCTOU race condition. ...
Feb 15, 2023This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on the NvmExpressDxe buffer, creating TOCTOU race conditions that can corrupt SMRAM...
Feb 15, 2023A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in AMI UEFI Firmware used in certain HP PC products could allow attackers to execute arbitrary c...
Feb 12, 2023CVE-2022-1537 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in GruntJS's file.copy operations that allows arbitrary file writes...
May 10, 2022This CVE describes a time-of-check-time-of-use (TOCTOU) vulnerability in Apache Tomcat that allows local attackers to escalate privileges. The vulnera...
Jan 27, 2022This vulnerability allows authenticated local attackers to execute arbitrary code with root privileges on Linux and Mac OS systems running Cisco AnyCo...
Oct 6, 2021This vulnerability allows an authenticated local attacker to perform DLL hijacking through a race condition in Cisco AnyConnect's signature verificati...
Jun 16, 2021A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Windows BitLocker allows an attacker with physical access to bypass security feat...
Jul 8, 2025A race condition vulnerability in Zoom Workplace Team Chat for Windows allows authenticated users to potentially access sensitive information through ...
Jul 15, 2024This vulnerability allows local attackers to escalate privileges by exploiting insecure temporary batch file execution in ESET Management Agent. Attac...
Feb 6, 2026This CVE describes a memory corruption vulnerability in Qualcomm sensor utility operations that could allow attackers to execute arbitrary code or cau...
Jan 7, 2026This vulnerability involves memory corruption when processing configuration calls from userspace in Qualcomm components, potentially allowing local at...
Jan 7, 2026This vulnerability allows memory corruption in Qualcomm camera drivers when processing I2C settings. Attackers could potentially execute arbitrary cod...
Jun 3, 2025This vulnerability involves memory corruption in the OIS packet parser, which could allow an attacker to execute arbitrary code or cause denial of ser...
Jun 3, 2025This CVE describes an Elevation of Privilege vulnerability in Symantec Endpoint Protection Windows Agent's ERASER Engine that allows attackers to dele...
Apr 30, 2025This CVE describes a time-of-check to time-of-use (TOCTOU) race condition in the virtio_vq_recordon function in bhyve's virtual I/O implementation. It...
Nov 12, 2024This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Craft CMS's GraphQL Asset mutation that allows DNS rebinding attacks. Attacke...
Feb 24, 2026This vulnerability allows local attackers with write access to the application's configuration directory to exploit a TOCTOU race condition during con...
Oct 17, 2025A time-of-check time-of-use race condition vulnerability in Intel Ethernet Adapter Complete Driver Pack software before version 1.5.1.0 allows unprivi...
Nov 11, 2025A race condition vulnerability in TeamViewer's directory validation logic allows local non-admin users to create arbitrary files with SYSTEM privilege...
Aug 26, 2025This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Adobe Commerce that allows attackers to bypass security featur...
Aug 12, 2025About CWE-367 (CWE-367)
Our database tracks 175 CVEs classified as CWE-367, with 16 rated critical and 120 rated high severity. The average CVSS score for CWE-367 vulnerabilities is 7.2.
External reference: View CWE-367 on MITRE CWE →
Monitor CWE-367 Vulnerabilities
Get alerted when new CWE-367 CVEs affect your infrastructure.
Start Monitoring Free