Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

697 CVEs tagged with CWE-36727 Critical, 353 High, 270 Medium, 47 Low, 0 Unrated.

CVE-2022-36929

Published Jan 9, 2023

The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the i…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-36927

Published Jan 9, 2023

Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate the…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-3590

Published Dec 14, 2022

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers ca…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44651

Published Dec 12, 2022

A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39908

Published Dec 8, 2022

TOCTOU vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45842

Published Nov 30, 2022

Unauth. Race Condition vulnerability in WP ULike Plugin <= 4.6.4 on WordPress allows attackers to increase/decrease rating scores.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34830

Published Nov 23, 2022

An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged user to make improper GPU processing operations to gain access to already freed mem…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30283

Published Nov 15, 2022

In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33986

Published Nov 15, 2022

DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. DMA attacks on the parameter buffer used by the software SMI…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33985

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which a…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33984

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33983

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions whic…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33909

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33908

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which ar…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33906

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions whi…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33905

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corruption (a TOCTOU attack). DMA transactions which are target…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 697 CVEsPage 21 of 28