CWE-367 检查时间与使用时间(TOCTOU)的竞争条件 类弱点 356 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-367 属于竞态条件漏洞,指系统在检查资源状态后、实际使用前,资源状态发生不可控变化,导致检查失效。攻击者利用这一时间窗口,通过并发操作篡改资源,从而绕过安全验证或执行未授权操作。开发者应避免在检查与使用间插入耗时操作,采用原子性操作或加锁机制确保状态一致性,以消除竞争条件带来的安全风险。
struct stat *sb; ... lstat("...",sb); // it has not been updated since the last time it was read printf("stated file\n"); if (sb->st_mtimespec==...){ print("Now updating things\n"); updateThings(); }if(!access(file,W_OK)) { f = fopen(file,"w+"); operate(f); ... } else { fprintf(stderr,"Unable to open file %s.\n",file); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2022-39908 | SAMSUNG Mobile devices 安全漏洞 — Samsung Mobile Devices | 6.9 | Medium | 2022-12-08 |
| CVE-2022-45842 | WordPress plugin WP Ulike 安全漏洞 — WP ULike (WordPress plugin) | 5.3 | Medium | 2022-11-30 |
| CVE-2022-22220 | Juniper Networks Junos OS 安全漏洞 — Junos OS | 5.9 | Medium | 2022-10-18 |
| CVE-2022-29800 | networkd-dispatcher 安全漏洞 — networkd-dispatcher | 4.7 | - | 2022-09-21 |
| CVE-2022-26859 | Dell BIOS 安全漏洞 — CPG BIOS | 6.1 | Medium | 2022-09-06 |
| CVE-2022-20909 | Cisco Nexus Dashboard 输入验证错误漏洞 — Cisco Nexus Dashboard | 6.0 | Medium | 2022-07-21 |
| CVE-2022-20906 | Cisco Nexus Dashboard 安全漏洞 — Cisco Nexus Dashboard | 6.0 | Medium | 2022-07-21 |
| CVE-2022-20907 | Cisco Nexus Dashboard 安全漏洞 — Cisco Nexus Dashboard | 6.0 | Medium | 2022-07-21 |
| CVE-2022-20908 | Cisco Nexus Dashboard 输入验证错误漏洞 — Cisco Nexus Dashboard | 6.0 | Medium | 2022-07-21 |
| CVE-2022-34899 | Parallels Access 安全漏洞 — Access | 7.8 | - | 2022-07-18 |
| CVE-2021-34986 | Corel Parallels Desktop 安全漏洞 — Desktop | 7.8 | - | 2022-07-15 |
| CVE-2022-33691 | SAMSUNG Mobile devices score driver 安全漏洞 — Samsung Mobile Devices | 6.2 | Medium | 2022-07-11 |
| CVE-2021-3969 | Lenovo Vantage 安全漏洞 — IMController | 7.8 | High | 2022-05-18 |
| CVE-2021-3922 | Lenovo Vantage 竞争条件问题漏洞 — IMController | 7.8 | High | 2022-05-18 |
| CVE-2022-1537 | Grunt 安全漏洞 — gruntjs/grunt | 7.0 | - | 2022-05-10 |
| CVE-2022-0915 | Logitech Sync for Windows 安全漏洞 — Sync | 6.0 | Medium | 2022-04-12 |
| CVE-2022-24413 | Dell Technologies Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS | 4.4 | Medium | 2022-04-12 |
| CVE-2022-27834 | Samsung SMR资源管理错误漏洞 — Samsung Mobile Devices | 2.9 | Low | 2022-04-11 |
| CVE-2022-0280 | McAfee Total Protection 安全漏洞 — McAfee Total Protection for Windows | 7.5 | High | 2022-03-10 |
| CVE-2022-23653 | B2_Command_Line_Tool 安全漏洞 — B2_Command_Line_Tool | 4.7 | Medium | 2022-02-23 |
| CVE-2022-23651 | b2-sdk-python 安全漏洞 — b2-sdk-python | 4.7 | Medium | 2022-02-23 |
| CVE-2022-23563 | Google Tensorflow 安全漏洞 — tensorflow | 7.1 | High | 2022-02-04 |
| CVE-2020-8562 | Kubernetes 安全漏洞 — Kubernetes | 2.2 | Low | 2022-02-01 |
| CVE-2022-23181 | Apache Tomcat 权限许可和访问控制问题漏洞 — Apache Tomcat | 7.0 | - | 2022-01-27 |
| CVE-2022-23029 | F5 BIG-IP 安全漏洞 — BIG-IP | 5.3 | - | 2022-01-25 |
| CVE-2021-4001 | Linux kernel 安全漏洞 — kernel | 4.1 | - | 2022-01-21 |
| CVE-2011-4126 | Calibre 授权问题漏洞 — Calibre | 8.1 | - | 2021-10-27 |
| CVE-2021-34788 | Cisco Anyconnect Secure Mobility Client 竞争条件问题漏洞 — Cisco AnyConnect Secure Mobility Client | 7.0 | High | 2021-10-06 |
| CVE-2021-3054 | Palo Alto Networks PAN-OS 安全漏洞 — PAN-OS | 7.2 | High | 2021-09-08 |
| CVE-2021-0289 | Juniper Networks Junos OS 安全漏洞 — Junos OS | 6.5 | Medium | 2021-07-15 |
CWE-367(检查时间与使用时间(TOCTOU)的竞争条件) 是常见的弱点类别,本平台收录该类弱点关联的 356 条 CVE 漏洞。