Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

743 CVEs tagged with CWE-36730 Critical, 375 High, 287 Medium, 49 Low, 2 Unrated.

CVE-2024-6601

Published Jul 9, 2024

A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39936

Published Jul 4, 2024

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant de…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39894

Published Jul 2, 2024

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Simila…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-0171

Published Jun 25, 2024

Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwis…

CVSS 5.3 · Medium

CVE-2024-36304

Published Jun 10, 2024

A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47280

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-of-use error in drm_getuniqu…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3292

Published May 17, 2024

A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could…

CVSS 8.2 · High

CVE-2024-3290

Published May 17, 2024

A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead t…

CVSS 8.2 · High

CVE-2024-21792

Published May 16, 2024

Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure v…

CVSS 4.7 · Medium

CVE-2024-29149

Published May 7, 2024

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check ti…

CVSS 7.4 · High

CVE-2024-2913

Published May 7, 2024

A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerabilit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34528

Published May 6, 2024

WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation.

CVSS 7.7 · High

CVE-2023-32156

Published May 3, 2024

Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27327

Published May 3, 2024

Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected install…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27323

Published May 3, 2024

Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-26974

Published May 1, 2024

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - resolve race condition during AER recovery During the PCI AER system's error recovery process,…

CVSS 7.8 · High
evidence mentions
12
Buzz score
37.1
Vendor/product tagsBeta · best-effort
Showing 401-425 of 743 CVEsPage 17 of 30