Vulnerabilities > Time-of-check Time-of-use (TOCTOU) Race Condition

DATE CVE VULNERABILITY TITLE RISK
2021-06-09 CVE-2020-11233 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Time-of-check time-of-use race condition While processing partition entries due to newly created buffer was read again from mmc without validation in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
high complexity
qualcomm CWE-367
7.0
2021-05-12 CVE-2021-23892 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Mcafee Endpoint Security for Linux Threat Prevention
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose of executing arbitrary code through insecure use of predictable temporary file locations.
local
high complexity
mcafee CWE-367
7.0
2021-04-30 CVE-2021-21539 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Dell Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability.
network
high complexity
dell CWE-367
7.1
2021-03-17 CVE-2020-11230 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes a physical address to user land in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
high complexity
qualcomm CWE-367
6.4
2021-03-17 CVE-2020-11220 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
local
high complexity
qualcomm CWE-367
6.4
2021-02-26 CVE-2021-23977 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Mozilla Firefox
Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories.
network
high complexity
mozilla CWE-367
5.3
2021-02-08 CVE-2021-26910 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
local
high complexity
firejail-project debian CWE-367
7.0
2021-01-30 CVE-2020-14418 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM.
local
high complexity
morphisec madshi cisco CWE-367
7.0
2021-01-26 CVE-2021-21615 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Jenkins
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
network
high complexity
jenkins CWE-367
5.3
2020-12-31 CVE-2020-35889 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Crayon Project Crayon
An issue was discovered in the crayon crate through 2020-08-31 for Rust.
network
high complexity
crayon-project CWE-367
8.1