CWE-362
Medium likelihoodConcurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
2,391 vulnerabilities with CWE-362
CVE-2024-2193
MEDIUM
CPU <Speculative Execution - Info Disclosure
CVSS 5.7
CVE-2024-24770
MEDIUM
vantage6 < 4.2.2 and >= 4.3.0 - Username Enumeration via Password Recovery and 2FA Lost Token Endpoints
CVSS 5.3
CVE-2024-27102
CRITICAL
Pterodactyl Wings < 1.11.9 - Path Traversal
CVSS 9.9
CVE-2024-21445
HIGH
Windows 10/11, Server 2022 - Elevation of Privilege via USB Print Driver Race Condition
CVSS 7.0
CVE-2024-21439
HIGH
Windows Telephony Server - Elevation of Privilege via Race Condition
CVSS 7.0
CVE-2024-26617
HIGH
Linux Kernel 6.7-6.7.2 - Race Condition in MMU Notifier Mechanism
CVSS 7.0
CVE-2024-23275
MEDIUM
macOS 12.0.0-12.7.3, 13.0.0-13.6.4, 14.0.0-14.3 - Unprotected User Data Exposure via Race Condition
CVSS 4.7
CVE-2024-23239
MEDIUM
iPadOS < 17.4 - Information Disclosure via Race Condition
CVSS 4.7
CVE-2024-23235
MEDIUM
iPadOS < 16.7.6 - Unauthorized Access to User-Sensitive Data via Race Condition
CVSS 4.7
CVE-2024-1949
LOW
Mattermost <8.1.9-9.4.2 - Privilege Escalation
CVSS 2.6
CVE-2024-26578
MEDIUM
Apache Answer <= 1.2.1 - Race Condition in User Registration
CVSS 5.9
CVE-2024-26585
MEDIUM
Linux Kernel 4.20.0-6.6.17, 5.16.0-6.1.83, 6.2.0-6.6.17, 6.7.0-6.7.5 - Race Condition in TLS Socket Close Handling
CVSS 4.7
CVE-2024-26583
MEDIUM
Linux Kernel 5.7.0-6.1.78, 5.16.0-5.15.159, 6.2.0-6.6.17, 6.7.0-6.7.5 - Race Condition in TLS Async Notification
CVSS 4.7
CVE-2024-0041
HIGH
Android - Local Privilege Escalation via SystemStatusAnimationSchedulerImpl Race Condition
CVSS 7.0
CVE-2024-24255
MEDIUM
PX4 Autopilot < 1.14.0 - Race Condition in Geofence and Mission Feasibility Checker
CVSS 4.2
CVE-2024-24254
MEDIUM
PX4 Autopilot < 1.14.0 - Race Condition in Geofence Data Loading
CVSS 4.2
CVE-2024-24864
MEDIUM
Linux Kernel - Null Pointer Dereference
CVSS 5.3
CVE-2024-24861
LOW
Linux kernel - Return Value Overflow
CVSS 3.3
CVE-2024-24860
MEDIUM
Linux Kernel - Null Pointer Dereference
CVSS 4.6
CVE-2024-24859
MEDIUM
Linux Kernel < 3.19.8 and >=4.0-rc1 <6.8-rc2 - Denial of Service via Bluetooth Sniff Interval Race Condition
CVSS 4.6
CVE-2024-24858
MEDIUM
Linux kernel < 3.19.8 and >=v4.0-rc1 <v6.8-rc2 - Denial of Service via Bluetooth Interval Set Race Condition
CVSS 4.6
CVE-2024-24857
MEDIUM
Linux kernel < 3.19.8 and >=v4.0-rc1 <v6.8-rc2 - Denial of Service via Bluetooth Connection Info Race Condition
CVSS 4.6
CVE-2024-24855
MEDIUM
Linux Kernel - Null Pointer Dereference
CVSS 5.0
CVE-2024-23196
MEDIUM
Linux Kernel < 5.5.19 - Denial of Service via Race Condition in snd_hdac_regmap_sync()
CVSS 5.3
CVE-2024-22386
MEDIUM
Linux kernel - Null Pointer Dereference
CVSS 5.3
Details
Vulnerabilities
2,391
Exploit Likelihood
Medium