Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

720 CVEs tagged with CWE-36728 Critical, 364 High, 281 Medium, 47 Low, 0 Unrated.

CVE-2023-43741

Published Dec 22, 2023

A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to bypass a symbolic li…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6803

Published Dec 21, 2023

A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. This vulnerability affected all versions of GitHub…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6690

Published Dec 21, 2023

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permiss…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-46649

Published Dec 21, 2023

A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an organization needs to be converted from a user.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45809

Published Dec 19, 2023

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-24351

Published Dec 16, 2023

TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before version 05.36.29, Kernel 5.4 version before 05.44.13, and Kernel…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42483

Published Dec 13, 2023

A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination o…

CVSS 6.3 · Medium

CVE-2023-5760

Published Nov 8, 2023

A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be furthe…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46725

Published Nov 2, 2023

FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side request forgery. In the Network modu…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34046

Published Oct 20, 2023

VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44188

Published Oct 11, 2023

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in telemetry processing of Juniper Networks Junos OS allows a network-based authenticated attacker to flood the s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43976

Published Oct 3, 2023

An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44128

Published Sep 27, 2023

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3891

Published Sep 15, 2023

Race condition in Lapce v0.2.8 allows an attacker to elevate privileges on the system

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-47631

Published Sep 14, 2023

Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management. Attackers can place DLLs into %PROGRAMDATA%…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 720 CVEsPage 18 of 29