Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

697 CVEs tagged with CWE-36727 Critical, 353 High, 270 Medium, 47 Low, 0 Unrated.

CVE-2022-32267

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM corruption (a TOCTOU attack) DMA transactions which are targ…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31243

Published Nov 15, 2022

Update description and links DMA transactions which are targeted at input buffers used for the software SMI handler used by the FvbServicesRuntimeDxe driver could cause SMRAM corr…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30774

Published Nov 15, 2022

DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack) DMA att…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34325

Published Nov 14, 2022

DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transact…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33982

Published Nov 14, 2022

DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on the SMI handler and lead to corruption of SMRAM. DMA attacks…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33907

Published Nov 14, 2022

DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver could cause SMRAM corruption through a TOCTOU attack... DMA tra…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30773

Published Nov 14, 2022

DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). DMA…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46853

Published Nov 3, 2022

Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22225

Published Oct 18, 2022

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22220

Published Oct 18, 2022

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS, Junos OS Evolved allows a network-based unauthenti…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41744

Published Oct 10, 2022

A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component could allow a local attacker to escalate privileges and turn a…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29800

Published Sep 21, 2022

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being disc…

CVSS 4.7 · Medium
evidence mentions
5
Buzz score
35.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2022-1974

Published Aug 31, 2022

A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacke…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20909

Published Jul 22, 2022

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insuff…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20908

Published Jul 22, 2022

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insuff…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20907

Published Jul 22, 2022

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insuff…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20906

Published Jul 22, 2022

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insuff…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 697 CVEsPage 22 of 28