CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,391 vulnerabilities with CWE-362
CVE-2023-38538 MEDIUM
Audio/Video Calls < Heap Use-After-Free - Info Disclosure
CVSS 5.0
CVE-2023-38537 MEDIUM
WhatsApp < 2.2338.12 - Use-After-Free via Network Transport Race Condition
CVSS 5.6
CVE-2023-4732 MEDIUM
Linux Kernel - Denial of Service via pfn_swap_entry_to_page Race Condition
CVSS 4.7
CVE-2023-5313 MEDIUM
phpkobo Ajax Poll Script 3.18 - Improper Enforcement of a Single, Unique Action in Poll Handler
CVSS 5.3
CVE-2023-42756 MEDIUM
Linux Kernel < 6.6 - Denial of Service via Netfilter IPSET Race Condition
CVSS 4.4
CVE-2023-41979 MEDIUM
macOS < 14.0 - Race Condition in File System Protection
CVSS 4.7
CVE-2023-41306 LOW
Huawei EMUI and HarmonyOS - Denial of Service via Bone Voice ID Trusted Application Mutex Mismanagement
CVSS 3.7
CVE-2023-3301 MEDIUM
QEMU < 8.0.3 - Denial of Service via Hot-Unplug Race Condition
CVSS 5.6
CVE-2023-41915 HIGH
OpenPMIx < 4.2.6 and 5.0.x < 5.0.1 - Arbitrary File Ownership via Race Condition
CVSS 8.1
CVE-2023-38616 HIGH
macOS Ventura <13.5 - Code Injection
CVSS 7.0
CVE-2023-20835 MEDIUM
Yocto - Use-After-Free via Race Condition in camsys
CVSS 6.4
CVE-2023-20834 MEDIUM
Android - Use-After-Free via Race Condition in pda
CVSS 6.4
CVE-2023-20827 MEDIUM
Android - Local Privilege Escalation via Race Condition in IMS Service
CVSS 6.4
CVE-2023-21290 MEDIUM
Android - Local Denial of Service via Race Condition in MmsProvider
CVSS 5.5
CVE-2023-34438 HIGH
Intel NUC BIOS Firmware - Privilege Escalation via Race Condition
CVSS 7.5
CVE-2023-34349 MEDIUM
Intel NUC Performance Kit and Mini PC Firmware - Privilege Escalation via Race Condition
CVSS 4.6
CVE-2023-22276 MEDIUM
Intel(R) Ethernet Controllers & Adapters E810 <1.7.2.4 - DoS
CVSS 6.5
CVE-2023-35378 HIGH
Windows Projected File System - Elevation of Privilege via TOCTOU Race Condition
CVSS 7.0
CVE-2023-20801 MEDIUM
Yocto - Use-After-Free via Race Condition in imgsys
CVSS 6.4
CVE-2023-4049 MEDIUM
Firefox < 116 - Use-After-Free via Reference Counting Race Condition
CVSS 5.9
CVE-2023-37904 LOW
Discourse < 3.0.6 - Race Condition in Invite Link User Creation
CVSS 2.6
CVE-2023-33951 MEDIUM
Linux Kernel < 6.3.9 - Information Disclosure via vmwgfx Driver Race Condition
CVSS 6.7
CVE-2023-32258 HIGH
Linux Kernel >=5.15 <5.15.145 - Remote Code Execution via SMB2_LOGOFF and SMB2_CLOSE Command Processing
CVSS 8.1
CVE-2023-32257 HIGH
Linux Kernel >=5.15 <5.15.145 - Remote Code Execution via SMB2 Session Handling Race Condition
CVSS 8.1
CVE-2023-38409 MEDIUM
Linux kernel <6.2.12 - Use After Free
CVSS 5.5
Details
Vulnerabilities 2,391
Exploit Likelihood Medium