Falhas do tipo CWE-367

504 resultados
CVE-2026-4878MEDIUMLibcap: libcap: privilege escalation via toctou race condition in cap_set_file()EPSS 0.2%CVE-2025-59497HIGHMicrosoft Defender for Linux Denial of Service VulnerabilityEPSS 0.2%CVE-2026-42336MEDIUMMaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL FetchEPSS 0.2%CVE-2026-27929HIGHWindows LUA File Virtualization Filter Driver Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-42592MEDIUMGotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routesEPSS 0.2%CVE-2021-4001A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a missing lock in kerneEPSS 0.2%CVE-2026-9796MEDIUMKeycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulnerabilityEPSS 0.2%CVE-2023-22883HIGHLocal Privilege Escalation in Zoom for Windows InstallersEPSS 0.2%CVE-2024-3290HIGHRace ConditionEPSS 0.2%CVE-2025-68146MEDIUMfilelock has TOCTOU race condition that allows symlink attacks during lock file creationEPSS 0.2%CVE-2026-45487HIGHWindows Program Compatibility Assistant Service Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-62724MEDIUMOpen OnDemand allowlist bypass using symlinks in directory downloads (TOCTOU)EPSS 0.2%CVE-2023-22397MEDIUMJunos OS Evolved: PTX10003: An attacker sending specific genuine packets will cause a memory leak in the PFE leading to a Denial of ServiceEPSS 0.2%CVE-2024-34528HIGHWordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter EPSS 0.2%CVE-2026-35362LOWuutils coreutils Missing TOCTOU Protection on Non-Linux Unix Platforms in Safe Traversal ModuleEPSS 0.2%CVE-2026-22820MEDIUMOutray cli is vulnerable to race conditions in tunnels creationEPSS 0.2%CVE-2023-20523MEDIUMTOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of sEPSS 0.2%CVE-2026-31824HIGHSylius has a Promotion Usage Limit Bypass via Race ConditionEPSS 0.2%CVE-2021-1567HIGHCisco AnyConnect Secure Mobility Client for Windows with VPN Posture (HostScan) Module DLL Hijacking VulnerabilityEPSS 0.2%CVE-2024-50592HIGHLocal Privilege Escalation via Race ConditionEPSS 0.2%