CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,391 vulnerabilities with CWE-362
CVE-2024-2193 MEDIUM
CPU <Speculative Execution - Info Disclosure
CVSS 5.7
CVE-2024-24770 MEDIUM
vantage6 < 4.2.2 and >= 4.3.0 - Username Enumeration via Password Recovery and 2FA Lost Token Endpoints
CVSS 5.3
CVE-2024-27102 CRITICAL
Pterodactyl Wings < 1.11.9 - Path Traversal
CVSS 9.9
CVE-2024-21445 HIGH
Windows 10/11, Server 2022 - Elevation of Privilege via USB Print Driver Race Condition
CVSS 7.0
CVE-2024-21439 HIGH
Windows Telephony Server - Elevation of Privilege via Race Condition
CVSS 7.0
CVE-2024-26617 HIGH
Linux Kernel 6.7-6.7.2 - Race Condition in MMU Notifier Mechanism
CVSS 7.0
CVE-2024-23275 MEDIUM
macOS 12.0.0-12.7.3, 13.0.0-13.6.4, 14.0.0-14.3 - Unprotected User Data Exposure via Race Condition
CVSS 4.7
CVE-2024-23239 MEDIUM
iPadOS < 17.4 - Information Disclosure via Race Condition
CVSS 4.7
CVE-2024-23235 MEDIUM
iPadOS < 16.7.6 - Unauthorized Access to User-Sensitive Data via Race Condition
CVSS 4.7
CVE-2024-1949 LOW
Mattermost <8.1.9-9.4.2 - Privilege Escalation
CVSS 2.6
CVE-2024-26578 MEDIUM
Apache Answer <= 1.2.1 - Race Condition in User Registration
CVSS 5.9
CVE-2024-26585 MEDIUM
Linux Kernel 4.20.0-6.6.17, 5.16.0-6.1.83, 6.2.0-6.6.17, 6.7.0-6.7.5 - Race Condition in TLS Socket Close Handling
CVSS 4.7
CVE-2024-26583 MEDIUM
Linux Kernel 5.7.0-6.1.78, 5.16.0-5.15.159, 6.2.0-6.6.17, 6.7.0-6.7.5 - Race Condition in TLS Async Notification
CVSS 4.7
CVE-2024-0041 HIGH
Android - Local Privilege Escalation via SystemStatusAnimationSchedulerImpl Race Condition
CVSS 7.0
CVE-2024-24255 MEDIUM
PX4 Autopilot < 1.14.0 - Race Condition in Geofence and Mission Feasibility Checker
CVSS 4.2
CVE-2024-24254 MEDIUM
PX4 Autopilot < 1.14.0 - Race Condition in Geofence Data Loading
CVSS 4.2
CVE-2024-24864 MEDIUM
Linux Kernel - Null Pointer Dereference
CVSS 5.3
CVE-2024-24861 LOW
Linux kernel - Return Value Overflow
CVSS 3.3
CVE-2024-24860 MEDIUM
Linux Kernel - Null Pointer Dereference
CVSS 4.6
CVE-2024-24859 MEDIUM
Linux Kernel < 3.19.8 and >=4.0-rc1 <6.8-rc2 - Denial of Service via Bluetooth Sniff Interval Race Condition
CVSS 4.6
CVE-2024-24858 MEDIUM
Linux kernel < 3.19.8 and >=v4.0-rc1 <v6.8-rc2 - Denial of Service via Bluetooth Interval Set Race Condition
CVSS 4.6
CVE-2024-24857 MEDIUM
Linux kernel < 3.19.8 and >=v4.0-rc1 <v6.8-rc2 - Denial of Service via Bluetooth Connection Info Race Condition
CVSS 4.6
CVE-2024-24855 MEDIUM
Linux Kernel - Null Pointer Dereference
CVSS 5.0
CVE-2024-23196 MEDIUM
Linux Kernel < 5.5.19 - Denial of Service via Race Condition in snd_hdac_regmap_sync()
CVSS 5.3
CVE-2024-22386 MEDIUM
Linux kernel - Null Pointer Dereference
CVSS 5.3
Details
Vulnerabilities 2,391
Exploit Likelihood Medium