csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the tem
Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the g
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability ex
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image prox
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-o
Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTok
In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) Convert macros to functions to avo
In the Linux kernel, the following vulnerability has been resolved: bonding: annotate data-races around slave->last_rx
util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vuln
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling a polled queue A us
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils during cross-device m
The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are init
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass
In the Linux kernel, the following vulnerability has been resolved: smb: client: make use of smbdirect_socket.recv_io.c
In the Linux kernel, the following vulnerability has been resolved: xfs: close crash window in attr dabtree inactivatio
In the Linux kernel, the following vulnerability has been resolved: ceph: fix i_nlink underrun during async unlink Dur
In the Linux kernel, the following vulnerability has been resolved: bpf: Require frozen map for calculating map hash C
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix btrfs_ioctl_space_info() slot_count TOCT
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an
rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows atta
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the chcon utility of uutils coreutils during recursive o
A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file a
In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malic
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Version
Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging
Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rend
Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnera
Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP reques
Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the s
OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against c
A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-pr
Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-con
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent th
The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) s
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.1
EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/At
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory wit
A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsi
Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file ap
Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the ren
filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to w
In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is
Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the rec
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Frequently Asked Questions
What is CWE-367?
CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-367?
There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.
How can I protect against CWE-367 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.
Detect CWE-367 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.
Get Started