Threats Tagged 'cwe-367'
View all threats tagged with 'cwe-367'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-367'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-48931: CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition in nodejs nodeCVE-2026-48931 0 A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. Join the discussion | CVE Database V5 | 06/22/2026, 18:59:30 UTC Added: 06/22/2026, 19:55:50 UTC |
CVE-2026-41045: CWE-367 Time-of-check time-of-use (TOCTOU) race condition in presire qSnapperCVE-2026-41045 0 A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user. Join the discussion | CVE Database V5 | 06/22/2026, 15:16:37 UTC Added: 06/22/2026, 15:39:21 UTC |
CVE-2026-48983: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition in mcdope pam_usbCVE-2026-48983 0 pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, a symlink race condition exists in per-device and per-user pad directory creation. pam_usb uses a check-then-act pattern: it calls lstat() to test for existence and then calls mkdir() separately to create the directory. A local attacker can win the race between these calls by replacing the target path with a symlink to a directory they control. If successful, one-time pad files may be written to an attacker-controlled location, potentially exposing future pad values before use or disrupting authentication. This issue has been fixed in version 0.9.2. Join the discussion | CVE Database V5 | 06/18/2026, 19:07:56 UTC Added: 06/18/2026, 19:51:23 UTC |
CVE-2026-54055: CWE-59: Improper Link Resolution Before File Access ('Link Following') in kovidgoyal kittyCVE-2026-54055 0 Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write to arbitrary files on the filesystem by exploiting a TOCTOU (Time-of-Check-Time-of-Use) race condition between symlink validation and file creation. The `os.open()` call used to create files does not use `O_NOFOLLOW`, allowing an attacker to create a symlink between the initial stat check and the actual file open, causing the write to follow the symlink to an arbitrary destination. Version 0.47.2 fixes the issue. Join the discussion | CVE Database V5 | 06/12/2026, 20:03:17 UTC Added: 06/12/2026, 20:09:28 UTC |
CVE-2026-50631: CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition in Apache Software Foundation Apache CXFCVE-2026-50631 0 A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue. Join the discussion | CVE Database V5 | 06/12/2026, 08:59:40 UTC Added: 06/12/2026, 09:54:39 UTC |
CVE-2026-24067: CWE-367 Time-of-check time-of-use (TOCTOU) race condition in Slate Digital LLC Slate Digital ConnectCVE-2026-24067 0 Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve code-signing information for the process. This PID-based client validation is subject to a time-of-check time-of-use race condition because process identifiers can be reused. A local attacker can exploit PID reuse so that validation is performed against a trusted process instead of the original connecting process. This allows unauthorized access to privileged helper functionality and may lead to local privilege escalation. Join the discussion | CVE Database V5 | 06/10/2026, 11:49:10 UTC Added: 06/10/2026, 12:13:03 UTC |
CVE-2024-43511: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition in Microsoft Windows 10 Version 1507CVE-2024-43511 0 Windows Kernel Elevation of Privilege Vulnerability Join the discussion | GCVE Database | 10/08/2024, 17:35:50 UTC Added: 06/09/2026, 19:18:39 UTC |
CVE-2026-45647: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition in Microsoft Microsoft Defender for Endpoint for MacCVE-2026-45647 0 Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 06/09/2026, 17:05:44 UTC Added: 06/09/2026, 17:27:05 UTC |
CVE-2026-45487: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition in Microsoft Windows 10 Version 21H2CVE-2026-45487 0 Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 06/09/2026, 17:04:43 UTC Added: 06/09/2026, 17:26:55 UTC |
CVE-2026-24065: CWE-367 Time-of-check time-of-use (TOCTOU) race condition in Waves Audio Ltd. Waves CentralCVE-2026-24065 0 Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-controlled process. This allows the attacker to invoke privileged operations, resulting in arbitrary code execution as root. The issue is fixed in version 16.6.2. Join the discussion | CVE Database V5 | 06/09/2026, 14:50:15 UTC Added: 06/09/2026, 15:25:52 UTC |
Showing 1 to 10 of 21 results