Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-367

MITRE ↗

CWE-367

32
CRITICAL
378
HIGH
280
MEDIUM
46
LOW
770 CVEs · Page 9/16
8.8
CVE-2023-32156

Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability allows network-adjacent att

8.8
CVE-2024-7348

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary

8.6
CVE-2024-39936

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x th

8.4
CVE-2023-33119

Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.

8.2
CVE-2024-3290

A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify insta

8.2
CVE-2024-3292

A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify

8.1
CVE-2024-1563

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external

8.1
CVE-2024-48322

UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.

7.8
CVE-2023-33046

Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.

7.8
CVE-2024-26218

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2024-26974

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - resolve race condition during AER rec

7.8
CVE-2023-27323

Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows

7.8
CVE-2024-28137

A local attacker with low privileges can perform a privil

7.8
CVE-2021-3899

There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an at

7.8
CVE-2024-36304

A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a loca

7.8
CVE-2022-27540

A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC pro

7.8
CVE-2024-38153

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2024-38186

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

7.8
CVE-2024-43882

In the Linux kernel, the following vulnerability has been resolved: exec: Fix ToCToU between perm check and set-uid/gid

7.8
CVE-2024-38406

Memory corruption while handling IOCTL calls in JPEG Encoder driver.

7.8
CVE-2024-38407

Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

7.8
CVE-2024-49046

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

7.8
CVE-2024-53289

Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged at

7.7
CVE-2024-34528

WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not u

7.5
CVE-2022-23084

The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This

7.5
CVE-2024-24993

A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated

7.5
CVE-2024-24995

A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated

7.5
CVE-2023-27327

Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows

7.5
CVE-2024-39894

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sud

7.5
CVE-2023-20578

A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or U

7.5
CVE-2024-5803

The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via a

7.5
CVE-2024-43452

Windows Registry Elevation of Privilege Vulnerability

7.4
CVE-2024-29149

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu

7.3
CVE-2024-10972

Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with

7.2
CVE-2023-32282

Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalatio

7.2
CVE-2024-29066

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

7.2
CVE-2024-22185

Time-of-check Time-of-use Race Condition in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to p

7.1
CVE-2024-29062

Secure Boot Security Feature Bypass Vulnerability

7.1
CVE-2024-27238

Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated

7.0
CVE-2022-48618 KEV

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadO

7.0
CVE-2024-21371

Windows Kernel Elevation of Privilege Vulnerability

7.0
CVE-2024-21433

Windows Print Spooler Elevation of Privilege Vulnerability

7.0
CVE-2021-33632

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-C

7.0
CVE-2021-47280

In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() Th

7.0
CVE-2024-30084

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

7.0
CVE-2024-30088 KEV

Windows Kernel Elevation of Privilege Vulnerability

7.0
CVE-2024-30099

Windows Kernel Elevation of Privilege Vulnerability

7.0
CVE-2024-35265

Windows Perception Service Elevation of Privilege Vulnerability

7.0
CVE-2024-39420

Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123

7.0
CVE-2024-39425

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-che

Frequently Asked Questions

What is CWE-367?

CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-367?

There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.

How can I protect against CWE-367 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.

Detect CWE-367 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.

Get Started