Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubu
Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic li
The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link att
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 12467
A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_par
procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() return
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allow
fts.c in coreutils 8.4 allows local users to delete arbitrary files.
Frequently Asked Questions
What is CWE-367?
CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-367?
There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.
How can I protect against CWE-367 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.
Detect CWE-367 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.
Get Started