Vulnerabilities > Time-of-check Time-of-use (TOCTOU) Race Condition

DATE CVE VULNERABILITY TITLE RISK
2023-02-01 CVE-2022-27538 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in HP products
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
local
high complexity
hp CWE-367
7.0
2023-02-01 CVE-2022-34398 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Dell products
Dell BIOS contains a Time-of-check Time-of-use vulnerability.
local
high complexity
dell CWE-367
7.0
2023-01-20 CVE-2022-48191 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Trendmicro Maximum Security 2022 17.7
A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malicious executable to a specific location and in the process of removal and restoral an attacker could replace an original folder with a mount point to an arbitrary location, allowing a escalation of privileges on an affected system.
local
high complexity
trendmicro CWE-367
7.0
2023-01-11 CVE-2021-46795 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in AMD products
A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.
local
high complexity
amd CWE-367
4.7
2023-01-11 CVE-2023-20523 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in AMD products
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.
high complexity
amd CWE-367
5.7
2023-01-09 CVE-2022-25716 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption in Multimedia Framework due to unsafe access to the data members
local
high complexity
qualcomm CWE-367
7.0
2023-01-03 CVE-2022-32638 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Google Android 11.0/12.0/13.0
In isp, there is a possible out of bounds write due to a race condition.
local
high complexity
google CWE-367
6.4
2022-12-22 CVE-2022-22753 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Mozilla Firefox
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory.
network
high complexity
mozilla CWE-367
7.1
2022-12-22 CVE-2022-26387 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Mozilla Firefox
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed.
network
high complexity
mozilla CWE-367
7.5
2022-12-14 CVE-2022-3590 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Wordpress
WordPress is affected by an unauthenticated blind SSRF in the pingback feature.
network
high complexity
wordpress CWE-367
5.9