The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during f
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -
The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during fil
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mv utility of uutils coreutils during cross-device
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the split utility of uutils coreutils. The program attem
OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows
FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod,
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk
acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local
Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perfor
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolv
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon recei
rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply a
Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked
OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the too
OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attack
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and
OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run appro
In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of
Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before as
Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Open Source Escargot allows Leveraging Race C
Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an u
LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thr
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, a symlink
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statist
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el
ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrai
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial
filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability
In the Linux kernel, the following vulnerability has been resolved: md: suspend array while updating raid_disks via sys
OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local attackers
The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before vers
A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when usin
OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attac
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, che
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun
A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont
Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attac
Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r
Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker
Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineerin
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv
OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows atta
A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function va
Frequently Asked Questions
What is CWE-367?
CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-367?
There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.
How can I protect against CWE-367 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.
Detect CWE-367 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.
Get Started