Vulnerabilities > Time-of-check Time-of-use (TOCTOU) Race Condition

DATE CVE VULNERABILITY TITLE RISK
2020-12-21 CVE-2020-25860 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Pengutronix Rauc
The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation.
network
high complexity
pengutronix CWE-367
6.6
2020-12-14 CVE-2020-27252 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Medtronic Mycarelink Smart Model 25000 Firmware
Medtronic MyCareLink Smart 25000 all versions are vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader.
network
high complexity
medtronic CWE-367
8.1
2020-11-12 CVE-2020-12926 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in AMD Trusted Platform Modules Reference
The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens.
high complexity
amd CWE-367
6.4
2020-10-30 CVE-2020-27014 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Trendmicro Antivirus 2020
Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash.\n\n\r\nAn attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
local
high complexity
trendmicro CWE-367
6.4
2020-10-22 CVE-2020-9939 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apple mac OS X
This issue was addressed with improved checks.
local
high complexity
apple CWE-367
6.4
2020-10-22 CVE-2020-9921 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apple mac OS X
A memory corruption issue was addressed with improved memory handling.
local
high complexity
apple CWE-367
7.0
2020-10-20 CVE-2020-3982 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in VMWare products
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device.
network
high complexity
vmware CWE-367
7.7
2020-10-20 CVE-2020-3981 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in VMWare products
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device.
network
high complexity
vmware CWE-367
5.8
2020-10-14 CVE-2020-8332 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Lenovo products
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution.
local
high complexity
lenovo CWE-367
6.4
2020-09-30 CVE-2020-14375 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5.
local
high complexity
dpdk opensuse canonical CWE-367
7.8