Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

698 CVEs tagged with CWE-36727 Critical, 353 High, 271 Medium, 47 Low, 0 Unrated.

CVE-2024-1563

Published Feb 22, 2024

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condit…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23084

Published Feb 15, 2024

The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43741

Published Dec 22, 2023

A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to bypass a symbolic li…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6803

Published Dec 21, 2023

A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6690

Published Dec 21, 2023

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permiss…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-46649

Published Dec 21, 2023

A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45809

Published Dec 19, 2023

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-24351

Published Dec 16, 2023

TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42483

Published Dec 13, 2023

A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination o…

CVSS 6.3 · Medium

CVE-2023-5760

Published Nov 8, 2023

A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be furthe…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46725

Published Nov 2, 2023

FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side request forgery. In the Network modu…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34046

Published Oct 20, 2023

VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44188

Published Oct 11, 2023

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in telemetry processing of Juniper Networks Junos OS allows a network-based authenticated attacker to flood the s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43976

Published Oct 3, 2023

An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 401-425 of 698 CVEsPage 17 of 28