WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition betwe
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x
Unauth. Race Condition vulnerability in WP ULike Plugin <= 4.6.4 on WordPress allows attackers to increase/decrease rati
b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK versi
B2 Command Line Tool is the official command line tool for the backblaze cloud storage service. Linux and Mac releases o
A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register
A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists bec
Dell PowerScale OneFS, versions 8.2.2-9.3.x, contain a time-of-check-to-time-of-use vulnerability. A local user with acc
A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a m
A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject cre
Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows a
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessin
Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any
Possible null pointer dereference due to race condition between timeline fence signal and time line fence destroy in Sna
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Preve
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Huawei Smartphone. Successful exploitation
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to m
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race conditio
While waiting for a response to a callback or listener request, non-secure clients can change permissions to shared memo
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users
Possible memory corruption due to Improper handling of hypervisor unmap operations for concurrent memory operations in S
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-4
A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a
All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-us
arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass a
A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enab
A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges t
Time-of-check time-of-use race condition While processing partition entries due to newly created buffer was read again f
A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authe
A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS
An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint v
In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
Time-of-check time-of-use vulnerability in the Crypto API Toolkit for Intel(R) SGX may allow a privileged user to potent
When user-defined ARP Policer is configured and applied on one or more Aggregated Ethernet (AE) interface units, a Time-
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be inval
Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability.
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifact
Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read
Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update sys
An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91.
An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and
An issue was discovered in the crayon crate through 2020-08-31 for Rust. A TOCTOU issue has a resultant memory safety vi
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they desc
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Work
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) f
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foun
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Frequently Asked Questions
What is CWE-367?
CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-367?
There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.
How can I protect against CWE-367 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.
Detect CWE-367 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.
Get Started