Windows Kernel Elevation of Privilege Vulnerability
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlegacy: Clear stale interrupts before resum
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be
Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct
Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authentic
A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on a
The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privilege
Nix is a package manager for Linux and other Unix systems. A fixed-output derivations on Linux can send file descriptors
In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states
ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-o
A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels
In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.
A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in rout
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS all
Windows Kernel Security Feature Bypass Vulnerability
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privi
Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user
Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potent
This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it
A vulnerability was discovered in Samsung Mobile Processor Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200
Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authen
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerabilit
In the Linux kernel, the following vulnerability has been resolved: ice: Don't process extts if PTP is disabled The ic
In the Linux kernel, the following vulnerability has been resolved: net: dsa: improve shutdown sequence Alexander Sver
In the Linux kernel, the following vulnerability has been resolved: fork: do not invoke uffd on fork if error occurs P
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a speciall
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This al
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use
Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s int
The Tillitis TKey signer device application is an ed25519 signing tool. A vulnerability has been found that makes it pos
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privi
Microsoft Outlook Security Feature Bypass Vulnerability
Windows Themes Remote Code Execution Vulnerability
A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.
An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race conditio
FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vul
The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-pr
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when pe
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr
Frequently Asked Questions
What is CWE-367?
CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-367?
There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.
How can I protect against CWE-367 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.
Detect CWE-367 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.
Get Started