<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – TOCTOU Race (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/toctou.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/toctou-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – TOCTOU Race (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:30 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-41259 – SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41259</guid>
    <pubDate>Wed, 03 Jun 2026 13:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41259</strong></p>
  <p>SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44469 – The affected product extracts installation files to a temporary directory with i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44469</guid>
    <pubDate>Tue, 26 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44469</strong></p>
  <p>The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29518 – Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29518</guid>
    <pubDate>Wed, 20 May 2026 13:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29518</strong></p>
  <p>Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitiv…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45675 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45675</guid>
    <pubDate>Fri, 15 May 2026 20:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45675</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regular signup handler (signup_handler in auths.py, line 663) was explicitly patched to prevent this race with the comment "Insert with default role first…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41702 – VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41702</guid>
    <pubDate>Fri, 15 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41702</strong></p>
  <p>VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7819 – Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager.

check_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7819</guid>
    <pubDate>Mon, 11 May 2026 16:17:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7819</strong></p>
  <p>Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager.  check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside their own storage directory pointing outside it and induce pgAdmin to write to any path reachable by the pgAdmin…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34354 – Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34354</guid>
    <pubDate>Fri, 08 May 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34354</strong></p>
  <p>Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs() function of the GPA service, by creating a log file and manipulating it into a symlink…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43433 – In the Linux kernel, the following vulnerability has been resolved:

rust_binder...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43433</guid>
    <pubDate>Fri, 08 May 2026 15:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43433</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rust_binder: avoid reading the written value in offsets array  When sending a transaction, its offsets array is first copied into the target proc's vma, and then the values are read back from there. This is normally fine because the vma is a read-only mapping, so the target process cannot change the value under us.  However, if…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41688 – Wallos is an open-source, self-hostable personal subscription tracker. In versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41688</guid>
    <pubDate>Thu, 07 May 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41688</strong></p>
  <p>Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL without CURLOPT_RESOLVE pinning on 10 of 11 outbound HTTP endpoints, leaving a DNS rebinding TOCTOU window. At time of publication, there are no publicly available patches.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41002 – The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41002</guid>
    <pubDate>Thu, 07 May 2026 04:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41002</strong></p>
  <p>The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); up…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34596 – Sandboxie-Plus is an open source sandbox-based isolation software for Windows. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34596</guid>
    <pubDate>Tue, 05 May 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34596</strong></p>
  <p>Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Check-to-Time-of-Use (TOCTOU) race condition exists during addon installation. When a user installs an addon through the SandMan interface, UpdUtil.exe is spawned as SYSTEM by SbieSvc but stages files in the user-writable %TEMP%\sandboxie-updater directory. After UpdUtil verifi…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-37531 – AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37531</guid>
    <pubDate>Fri, 01 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-37531</strong></p>
  <p>AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP entry names but does not check for dot notation directory traversal sequences it only blocks absolute paths. The zread extraction function uses openat(workdirfd, f…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31700 – In the Linux kernel, the following vulnerability has been resolved:

net/packet:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31700</guid>
    <pubDate>Fri, 01 May 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31700</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()  In tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points directly into the mmap'd TX ring buffer shared with userspace. The kernel validates the header via __packet_snd_vnet_parse() but then re-reads all fields later in virtio_net_hdr_to_skb(). A concurre…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31641 – In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31641</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31641</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix RxGK token loading to check bounds  rxrpc_preparse_xdr_yfs_rxgk() reads the raw key length and ticket length from the XDR token as u32 values and passes each through round_up(x, 4) before using the rounded value for validation and allocation.  When the raw length is >= 0xfffffffd, round_up() wraps to 0, so the bounds…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35352 – A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo util...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35352</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35352</strong></p>
  <p>A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabl…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41651 – PackageKit is a a D-Bus abstraction layer that allows the user to manage package...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41651</guid>
    <pubDate>Wed, 22 Apr 2026 14:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41651</strong></p>
  <p>PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31446 – In the Linux kernel, the following vulnerability has been resolved:

ext4: fix u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31446</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31446</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ext4: fix use-after-free in update_super_work when racing with umount  Commit b98535d09179 ("ext4: fix bug_on in start_this_handle during umount filesystem") moved ext4_unregister_sysfs() before flushing s_sb_upd_work to prevent new error work from being queued via /proc/fs/ext4/xx/mb_groups reads during unmount. However, this i…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41055 – WWBN AVideo is an open source video platform. In versions 29.0 and below, an inc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41055</guid>
    <pubDate>Tue, 21 Apr 2026 23:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41055</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the actual HTTP request redirects traffic to internal endpoints. Commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 contains an updated fix.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40943 – Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40943</guid>
    <pubDate>Tue, 21 Apr 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40943</strong></p>
  <p>Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can cause the server to panic with send on closed channel. The heartbeat() method uses a blocking channel send while holding a mutex, and under specific timing with concurrent close() calls, this can lead to either a deadlock (channel buffer full) or a panic…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27929 – Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27929</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27929</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30332 – A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30332</guid>
    <pubDate>Thu, 02 Apr 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30332</strong></p>
  <p>A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows attackers to escalate privileges and execute arbitrary code via replacing a legitimate script with a crafted payload during the flashing process.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32232 – ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32232</guid>
    <pubDate>Thu, 12 Mar 2026 19:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32232</strong></p>
  <p>ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31824 – Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31824</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31824</strong></p>
  <p>Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage limit enforcement. The same class of vulnerability affects the promotion usage limit (the global used counter on Promotion entities), coupon usage limit (the global used counter on PromotionCoupon entities), and coupon per-customer usage limit (the…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2364 – If a legitimate user confirms a self-update prompt or initiate an installation o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2364</guid>
    <pubDate>Tue, 10 Mar 2026 17:39:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2364</strong></p>
  <p>If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low privileged local attacker can gain elevated rights due to a TOCTOU vulnerability in the CODESYS installer.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26017 – CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26017</guid>
    <pubDate>Fri, 06 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26017</strong></p>
  <p>CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27750 – Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27750</guid>
    <pubDate>Thu, 05 Mar 2026 15:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27750</strong></p>
  <p>Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without revalidating the target path. A local attacker can replace a previously scanned directory with a junction or reparse point…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28289 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28289</guid>
    <pubDate>Tue, 03 Mar 2026 23:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28289</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnera…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26224 – Intego Log Reporter, a macOS diagnostic utility bundled with Intego security pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26224</guid>
    <pubDate>Thu, 12 Feb 2026 22:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26224</strong></p>
  <p>Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerability. A root-executed diagnostic script creates and writes files in /tmp without enforcing secure directory handling, introducing a time-of-check to time-of-use (TOCTOU) race condition. A local unprivil…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-31324 – A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31324</guid>
    <pubDate>Wed, 11 Feb 2026 15:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-31324</strong></p>
  <p>A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20548 – A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20548</guid>
    <pubDate>Wed, 11 Feb 2026 15:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20548</strong></p>
  <p>A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25728 – ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25728</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25728</strong></p>
  <p>ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability exists in ClipBucket's avatar and background image upload functionality. The application moves uploaded files to a web-accessible location before validating them, creating a window where an attacker can execute arbitrary PHP code before the file is del…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21523 – Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21523</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21523</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21240 – Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21240</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21240</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23988 – Rufus is a utility that helps format and create bootable USB flash drives. Versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23988</guid>
    <pubDate>Thu, 22 Jan 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23988</strong></p>
  <p>Rufus is a utility that helps format and create bootable USB flash drives. Versions 4.11 and below contain a race condition (TOCTOU) in src/net.c during the creation, validation, and execution of the Fido PowerShell script. Since Rufus runs with elevated privileges (Administrator) but writes the script to the %TEMP% directory (writeable by standard users) without locking the file, a local attacke…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20831 – Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20831</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20831</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20816 – Time-of-check time-of-use (toctou) race condition in Windows Installer allows an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20816</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20816</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20809 – Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20809</guid>
    <pubDate>Tue, 13 Jan 2026 18:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20809</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61037 – A local privilege escalation vulnerability exists in SevenCs ORCA G2 2.0.1.35 (E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61037</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61037</guid>
    <pubDate>Wed, 31 Dec 2025 16:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61037</strong></p>
  <p>A local privilege escalation vulnerability exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The flaw is a Time-of-Check Time-of-Use (TOCTOU) race condition in the license management logic. The regService process, which runs with SYSTEM privileges, creates a fixed directory and writes files without verifying whether the path is an NTFS reparse point. By exploiting this race condition, an…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61037">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58407 – Kernel or driver software installed on a Guest VM may post improper commands to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58407</guid>
    <pubDate>Mon, 17 Nov 2025 18:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58407</strong></p>
  <p>Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-64180 – Manager-io/Manager is accounting software. In Manager Desktop and Server version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64180</guid>
    <pubDate>Fri, 07 Nov 2025 04:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-64180</strong></p>
  <p>Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network resources. The flaw lies in the fundamental design of the DNS validation mechanism. A Time-of-Check Time-of-Use (TOCTOU) condition that allows attackers to bypass network isolation and access internal services, cloud met…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34294 – Wazuh's File Integrity Monitoring (FIM), when configured with automatic threat r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34294</guid>
    <pubDate>Tue, 28 Oct 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34294</strong></p>
  <p>Wazuh's File Integrity Monitoring (FIM), when configured with automatic threat removal, contains a time-of-check/time-of-use (TOCTOU) race condition that can allow a local, low-privileged attacker to cause the Wazuh service (running as NT AUTHORITY\SYSTEM) to delete attacker-controlled files or paths. The root cause is insufficient synchronization and lack of robust final-path validation in the t…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59497 – Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59497</guid>
    <pubDate>Tue, 14 Oct 2025 17:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59497</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59261 – Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Componen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59261</guid>
    <pubDate>Tue, 14 Oct 2025 17:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59261</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55696 – Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55696</guid>
    <pubDate>Tue, 14 Oct 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55696</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55680 – Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55680</guid>
    <pubDate>Tue, 14 Oct 2025 17:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55680</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55236 – Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55236</guid>
    <pubDate>Tue, 09 Sep 2025 17:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55236</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54093 – Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54093</guid>
    <pubDate>Tue, 09 Sep 2025 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54093</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53788 – Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53788</guid>
    <pubDate>Tue, 12 Aug 2025 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53788</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50158 – Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50158</guid>
    <pubDate>Tue, 12 Aug 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50158</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49730 – Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS sched...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49730</guid>
    <pubDate>Tue, 08 Jul 2025 17:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49730</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34027 – The Versa Concerto SD-WAN orchestration platform is vulnerable to an authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34027</guid>
    <pubDate>Wed, 21 May 2025 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34027</strong></p>
  <p>The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combination with a race condition to achieve remote code execution via path loading manipulation, allowing an u…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29969 – Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29969</guid>
    <pubDate>Tue, 13 May 2025 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29969</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29833 – Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29833</guid>
    <pubDate>Tue, 13 May 2025 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29833</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42446 – APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-ch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42446</guid>
    <pubDate>Tue, 13 May 2025 14:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42446</strong></p>
  <p>APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerability may lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3886 – An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3886</guid>
    <pubDate>Sun, 27 Apr 2025 11:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3886</strong></p>
  <p>An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32784 – conda-forge-webservices is the web app deployed to run conda-forge admin command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32784</guid>
    <pubDate>Tue, 15 Apr 2025 22:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32784</strong></p>
  <p>conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025.4.10, a race condition vulnerability has been identified in the conda-forge-webservices component used within the shared build infrastructure. This vulnerability, categorized as a Time-of-Check to Time-of-Use (TOCTOU) issue, can be exploited to introduce unauthorized modificati…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27812 – MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27812</guid>
    <pubDate>Thu, 10 Apr 2025 13:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27812</strong></p>
  <p>MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-21191 – Time-of-check time-of-use (toctou) race condition in Windows Local Security Auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21191</guid>
    <pubDate>Tue, 08 Apr 2025 18:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-21191</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54084 – APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-ch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54084</guid>
    <pubDate>Tue, 11 Mar 2025 14:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54084</strong></p>
  <p>APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerability may lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53694 – A time-of-check time-of-use (TOCTOU) race condition vulnerability has been repor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53694</guid>
    <pubDate>Fri, 07 Mar 2025 17:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53694</strong></p>
  <p>A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources.  We have already fixed the vulnerability in the following versions: QVPN Device Client for Mac 2.2.5 and later Qsync for Mac 5.1.3 and late…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22224 – VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22224</guid>
    <pubDate>Tue, 04 Mar 2025 12:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22224</strong></p>
  <p>VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23359 – NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23359</guid>
    <pubDate>Wed, 12 Feb 2025 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23359</strong></p>
  <p>NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48394 – A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48394</guid>
    <pubDate>Wed, 05 Feb 2025 22:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48394</strong></p>
  <p>A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which could allow an unprivileged user to exploit this flaw and gain SYSTEM-level access on the device. The vulnerability affects version 5.24.3 and before of the software.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42444 – APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Rac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42444</guid>
    <pubDate>Tue, 14 Jan 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42444</strong></p>
  <p>APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead to execution of arbitrary code on the target device.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-56337 – Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56337</guid>
    <pubDate>Fri, 20 Dec 2024 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-56337</strong></p>
  <p>Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are  known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions  may also be affected.   The mitigation for C…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-50379 – Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50379</guid>
    <pubDate>Tue, 17 Dec 2024 13:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-50379</strong></p>
  <p>Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration).  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.  The following versions were EOL at the time…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53289 – Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Cond...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53289</guid>
    <pubDate>Wed, 11 Dec 2024 08:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53289</strong></p>
  <p>Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27134 – Excessive directory permissions in MLflow leads to local privilege escalation wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27134</guid>
    <pubDate>Mon, 25 Nov 2024 14:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27134</strong></p>
  <p>Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5803 – The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a loc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5803</guid>
    <pubDate>Thu, 03 Oct 2024 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5803</strong></p>
  <p>The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-0132 – NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0132</guid>
    <pubDate>Thu, 26 Sep 2024 06:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-0132</strong></p>
  <p>NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, informa…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43882 – In the Linux kernel, the following vulnerability has been resolved:

exec: Fix T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43882</guid>
    <pubDate>Wed, 21 Aug 2024 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43882</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  exec: Fix ToCToU between perm check and set-uid/gid usage  When opening a file for exec via do_filp_open(), permission checking is done against the file's metadata at that moment, and on success, a file pointer is passed back. Much later in the execve() code path, the file metadata (specifically mode, uid, and gid) is used to de…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39425 – Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39425</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39425</strong></p>
  <p>Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploitation of this issue require local low-privilege access to the affected system and attack complexity is high.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39420 – Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39420</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39420</strong></p>
  <p>Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary code execution. This vulnerability arises when the timing of actions changes the state of a resource between the checking of a condition and…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20578 – A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20578</guid>
    <pubDate>Tue, 13 Aug 2024 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20578</strong></p>
  <p>A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7348 – Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7348</guid>
    <pubDate>Thu, 08 Aug 2024 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7348</strong></p>
  <p>Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27540 – A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27540</guid>
    <pubDate>Fri, 28 Jun 2024 19:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27540</strong></p>
  <p>A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28137 – A local attacker with low privileges can perform a privilege escalation with an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28137</guid>
    <pubDate>Tue, 14 May 2024 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28137</strong></p>
  <p>A local attacker with low privileges can perform a privilege escalation with an init script due to a  TOCTOU vulnerability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34528 – WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34528</guid>
    <pubDate>Mon, 06 May 2024 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34528</strong></p>
  <p>WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24995 – A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24995</guid>
    <pubDate>Fri, 19 Apr 2024 02:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24995</strong></p>
  <p>A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24993 – A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24993</guid>
    <pubDate>Fri, 19 Apr 2024 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24993</strong></p>
  <p>A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33632 – Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33632</guid>
    <pubDate>Mon, 25 Mar 2024 07:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33632</strong></p>
  <p>Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad/main.C.  This issue affects iSulad: 2.0.18-13, from 2.1.4-1 through 2.1.4-2.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5760 – A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5760</guid>
    <pubDate>Wed, 08 Nov 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5760</strong></p>
  <p>A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38041 – A logged in user may elevate its permissions by abusing a Time-of-Check to Time-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38041</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38041</strong></p>
  <p>A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43976 – An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43976</guid>
    <pubDate>Tue, 03 Oct 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43976</strong></p>
  <p>An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27470 – BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27470</guid>
    <pubDate>Mon, 11 Sep 2023 15:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27470</strong></p>
  <p>BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37250 – Unity Parsec has a TOCTOU race condition that permits local attackers to escalat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37250</guid>
    <pubDate>Sun, 20 Aug 2023 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37250</strong></p>
  <p>Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26299 – A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26299</guid>
    <pubDate>Fri, 30 Jun 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26299</strong></p>
  <p>A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31639 – Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31639</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31639</strong></p>
  <p>Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31638 – Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31638</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31638</strong></p>
  <p>Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31637 – Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31637</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31637</strong></p>
  <p>Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31636 – Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31636</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31636</strong></p>
  <p>Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31635 – Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31635</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31635</strong></p>
  <p>Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43778 – Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43778</guid>
    <pubDate>Mon, 12 Jun 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43778</strong></p>
  <p>Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43777 – Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43777</guid>
    <pubDate>Mon, 12 Jun 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43777</strong></p>
  <p>Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27541 – Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27541</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27541</guid>
    <pubDate>Mon, 12 Jun 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27541</strong></p>
  <p>Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27541">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27539 – Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27539</guid>
    <pubDate>Mon, 12 Jun 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27539</strong></p>
  <p>Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26356 – A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM foll...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26356</guid>
    <pubDate>Tue, 09 May 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26356</strong></p>
  <p>A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43946 – Multiple vulnerabilities including an incorrect permission assignment for critic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43946</guid>
    <pubDate>Tue, 11 Apr 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43946</strong></p>
  <p>Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32477 – An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32477</guid>
    <pubDate>Wed, 15 Feb 2023 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32477</strong></p>
  <p>An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This attack can be mitigated using IOMMU protection for the ACPI runtime memory used for the command buffer. This attack can be miti…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32475 – An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32475</guid>
    <pubDate>Wed, 15 Feb 2023 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32475</strong></p>
  <p>An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel, which also protected chipset and OEM chipset code.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32475">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
