The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local
In the Linux kernel, the following vulnerability has been resolved: rust_binder: avoid reading the written value in off
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local at
A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use iss
In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attack
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Betwee
In the Linux kernel, the following vulnerability has been resolved: sched/psi: fix race between file release and pressu
In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, attempt 4
In the Linux kernel, the following vulnerability has been resolved: xsk: cache csum_start/csum_offset to fix TOCTOU in
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between chec
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could resul
In the Linux kernel, the following vulnerability has been resolved: rbd: eliminate a race in lock_dwork draining on unm
When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a
The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c sn
Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-
The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS acce
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise d
Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external me
ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a Time-of-Check to Time-of-Use (TOCTOU) ra
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary fi
A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incomi
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execu
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevat
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretraine
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows a
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch
PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on
Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escal
A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Di
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u
9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetchin
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,
A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attac
Rufus is a utility that helps format and create bootable USB flash drives. Versions 4.11 and below contain a race condit
If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low pr
OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local cod
Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-chec
Frequently Asked Questions
What is CWE-367?
CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-367?
There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.
How can I protect against CWE-367 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.
Detect CWE-367 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.
Get Started