Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalati
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.
A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon
A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to ex
In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use con
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down
In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 1
TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code.
In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race cond
u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition a
u'Non-secure memory is touched multiple times during TrustZone\u2019s execution and can lead to privilege escalation or
A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt me
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A
In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulne
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-4
The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerab
In SurfaceFlinger, there is a possible use after free due to a race condition. This could lead to local escalation of pr
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo an
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.6. A local user may be able t
Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Block
A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook mod
The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happe
A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Ent
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writ
Creative Cloud Desktop Application versions 5.0 and earlier have a time-of-check to time-of-use (toctou) race condition
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Work
Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible
A privilege escalation vulnerability in Juniper Networks Junos OS devices configured with dual Routing Engines (RE), Vir
A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise M
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combi
Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core
CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descen
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and woul
Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devis
STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the H
In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain c
Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF is
An ability to process crash dumps under root privileges and inappropriate symlinks handling could lead to a local privil
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An at
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 E
A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for
All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is
Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pul
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AU
Frequently Asked Questions
What is CWE-367?
CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-367?
There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.
How can I protect against CWE-367 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.
Detect CWE-367 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.
Get Started