This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39
Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach
memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Conn
DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could c
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handl
A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43
Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivi
In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in pro
An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged user to make improper GP
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming t
Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromis
Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe conc
Tensorflow is an Open Source Machine Learning Framework. In multiple places, TensorFlow uses `tempfile.mktemp` to create
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write a
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1
An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN conf
In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repo
Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack d
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component coul
DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corr
DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM co
DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM cor
DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRA
DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler could cause SMRAM cor
DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler could cause SMRAM c
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a loca
TOCTOU vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attac
In vow driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of pri
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that
In jpeg, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wi
DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have be
DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver coul
DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on th
DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been
Update description and links DMA transactions which are targeted at input buffers used for the software SMI handler used
DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM c
DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMR
DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. D
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to int
Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending maliciou
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks J
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networ
Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent be
Frequently Asked Questions
What is CWE-367?
CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-367?
There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.
How can I protect against CWE-367 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.
Detect CWE-367 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.
Get Started