cwe-367
Safeguard articles tagged "cwe-367" — guides, analysis, and best practices for software supply chain and application security.
6 articles
CVE-2023-35311: Microsoft Outlook Security Feature Bypass Vulnerability
CVE-2023-35311 affects Microsoft Outlook and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-07-11.
CVE-2022-48618: Apple Multiple Products Memory Corruption Vulnerability
CVE-2022-48618 affects Apple Multiple Products and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-01-31.
CVE-2024-30088: Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
CVE-2024-30088 affects Microsoft Windows and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-10-15.
CVE-2025-22224: VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
CVE-2025-22224 affects VMware ESXi and Workstation and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-03-04.
CVE-2025-38352: Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
CVE-2025-38352 affects Linux Kernel and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-09-04.
Time-of-check to time-of-use (TOCTOU) race condition vulnerabilities
TOCTOU race conditions let attackers swap a resource between a security check and its use. Real CVEs, exploit mechanics, and prevention patterns explained.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.