Vulnerabilities > Time-of-check Time-of-use (TOCTOU) Race Condition

DATE CVE VULNERABILITY TITLE RISK
2020-07-15 CVE-2020-14675 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
high complexity
oracle opensuse CWE-367
7.5
2020-07-15 CVE-2020-14674 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
high complexity
oracle opensuse CWE-367
7.5
2020-06-18 CVE-2020-13882 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition.
local
high complexity
cisofy fedoraproject CWE-367
4.2
2020-06-16 CVE-2020-13162 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Pulsesecure products
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.
local
high complexity
pulsesecure CWE-367
7.0
2020-06-15 CVE-2017-18869 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Chownr Project Chownr
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
local
high complexity
chownr-project CWE-367
2.5
2020-06-11 CVE-2020-0204 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Google Android 10.0
In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use condition.
local
high complexity
google CWE-367
7.0
2020-06-10 CVE-2020-2032 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Paloaltonetworks Globalprotect
A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges.
local
high complexity
paloaltonetworks CWE-367
7.0
2020-06-02 CVE-2020-3680 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
A race condition can occur when using the fastrpc memory mapping API.
local
high complexity
qualcomm CWE-367
7.0
2020-05-29 CVE-2020-3957 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in VMWare Fusion, Horizon Client and Remote Console
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener.
local
high complexity
vmware CWE-367
7.0
2020-04-22 CVE-2020-8833 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity.
local
high complexity
canonical apport-project CWE-367
4.7