CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,384 vulnerabilities with CWE-362
CVE-2024-57913 MEDIUM
Linux Kernel 2.6.35-6.12.10 - Race Condition in USB Gadget FunctionFS Bind
CVSS 4.7
CVE-2024-57893 MEDIUM
Linux Kernel < 6.1.124, 6.2.0-6.6.70, 6.7.0-6.12.9 - Race Condition in ALSA Sequencer OSS SysEx Message Handling
CVSS 6.3
CVE-2024-12747 MEDIUM
rsync - Privilege Escalation
CVSS 5.6
CVE-2024-57876 HIGH
Linux Kernel 5.10.173-5.11 - Race Condition in DRM DP MST Topology Manager
CVSS 7.0
CVE-2024-56788 MEDIUM
Linux Kernel 6.12-6.12.6 - Race Condition in Ethernet TX SKB Handling
CVSS 4.7
CVE-2024-56441 MEDIUM
Huawei EMUI and HarmonyOS - Race Condition in Bastet Module
CVSS 4.1
CVE-2024-54120 MEDIUM
Distributed Notification Module - Info Disclosure
CVSS 4.1
CVE-2024-56706 MEDIUM
Linux Kernel 6.12-6.12.1 - Out-of-bounds Read in SDB Memory Allocation
CVSS 6.3
CVE-2024-53476 MEDIUM
SimplCommerce - Race Condition in Inventory Tracking
CVSS 5.9
CVE-2024-56664 HIGH
Linux Kernel - Use-After-Free in BPF Sockmap Element Replacement
CVSS 7.0
CVE-2024-56637 MEDIUM
Linux Kernel - Use-After-Free via ipset Module Unload Race Condition
CVSS 4.7
CVE-2024-56635 HIGH
Linux Kernel 6.2-6.6.65, 6.7-6.12.4, 6.13 - Use-After-Free in default_operstate
CVSS 7.0
CVE-2024-56576 MEDIUM
Linux Kernel - Use-After-Free in tc358743 Probe Error Path
CVSS 4.7
CVE-2024-56568 MEDIUM
Linux kernel - Null Pointer Dereference
CVSS 4.7
CVE-2024-56556 HIGH
Linux Kernel 6.12-6.12.3 - Use-After-Free in binder_add_freeze_work
CVSS 7.0
CVE-2024-56552 MEDIUM
Linux Kernel 6.8-6.12.3 - Race Condition in drm/xe/guc_submit
CVSS 4.7
CVE-2024-56540 MEDIUM
Linux Kernel - Race Condition in IVPU Driver
CVSS 4.7
CVE-2024-53186 HIGH
Linux Kernel - Use-After-Free in ksmbd_conn_handler_loop via Race Condition
CVSS 7.0
CVE-2024-52906 MEDIUM
IBM AIX 7.2-7.3 and VIOS 3.1-4.1 - Denial of Service via TCP/IP Kernel Extension
CVSS 5.5
CVE-2024-53160 MEDIUM
Linux Kernel 6.3-6.6.63, 6.7-6.11.10, 6.12-6.12.1 - Data Race in RCU kvfree_call_rcu Monitor Work Timer
CVSS 4.7
CVE-2024-11144 HIGH
LightFTP >=2.3 <2.3 - Unauthenticated Denial of Service via Thread Safety Issue
CVSS 7.5
CVE-2024-48872 MEDIUM
Mattermost 9.5.0-9.5.12 9.11.0-9.11.4 10.0.0-10.0.2 10.1.0-10.1.2 - Race Condition in Failed Login Attempts Check
CVSS 4.8
CVE-2024-47892 HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 RTM1 - Use-After-Free via GPU System Calls
CVSS 7.8
CVE-2024-46971 HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 RTM1 and >=24.2 RTM2 - Use-After-Free via GPU System Calls
CVSS 7.8
CVE-2024-54122 MEDIUM
HarmonyOS - Denial of Service via Concurrent Variable Access in Ability Module
CVSS 6.2
Details
Vulnerabilities 2,384
Exploit Likelihood Medium