CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,393 vulnerabilities with CWE-362
CVE-2021-0564 MEDIUM
Android - Use-After-Free via Race Condition in CryptoPlugin.cpp
CVSS 6.4
CVE-2021-24377 HIGH
Autoptimize < 2.7.8 - Remote Code Execution via Import Settings Race Condition
CVSS 8.1
CVE-2021-0533 HIGH
Android - Memory Corruption due to Race Condition in Memory Management Driver
CVSS 7.0
CVE-2021-0532 HIGH
Android - Memory Corruption via Race Condition in Memory Management Driver
CVSS 7.0
CVE-2021-0520 HIGH
Android 10-11 - Use-After-Free via Race Condition in MemoryFileSystem
CVSS 7.0
CVE-2021-0509 HIGH
Android - Use-After-Free via Race Condition in CryptoPlugin.cpp
CVSS 7.0
CVE-2021-0508 HIGH
Android 8.1-11 - Use-After-Free via Race Condition in DrmPlugin.cpp
CVSS 7.0
CVE-2021-0476 HIGH
Android - Use-After-Free via Race Condition in FindOrCreatePeer
CVSS 7.0
CVE-2021-25395 MEDIUM KEV
MFC Charger Driver <SMR MAY-2021 Release 1 - Privilege Escalation
CVSS 6.4
CVE-2021-25394 MEDIUM KEV
MFC Charger Driver <SMR MAY-2021 Release 1 - Use After Free
CVSS 6.4
CVE-2021-1900 HIGH
Qualcomm APQ8009 Firmware - Use-After-Free via Display Race Condition
CVSS 8.4
CVE-2021-30465 HIGH
runc < 1.0.0-rc95 - Container Filesystem Breakout via Directory Traversal Race Condition
CVSS 8.5
CVE-2021-27925 MEDIUM
Couchbase Server <6.6.2 - Info Disclosure
CVSS 4.4
CVE-2021-32921 MEDIUM
prosody < 0.11.9 - Timing Attack via Non-Constant-Time String Comparison
CVSS 5.9
CVE-2021-20181 HIGH
QEMU <= 5.2.0 - Use-After-Free via 9pfs Server Race Condition
CVSS 7.5
CVE-2021-32399 HIGH
Linux Kernel < 5.12.2 - Race Condition in HCI Controller Removal
CVSS 7.0
CVE-2021-27216 MEDIUM
Exim < 4.94.2 - Unauthenticated Arbitrary File Deletion via delete_pid_file Race Condition
CVSS 6.3
CVE-2021-0270 HIGH
Juniper Junos OS 18.1R2-18.1R3-S10 - Denial of Service via Inline J-Flow Race Condition
CVSS 7.5
CVE-2021-0258 MEDIUM
Juniper Junos OS 17.2-19.4 - Denial of Service via Transit TCPv6 Packet Handling
CVSS 5.9
CVE-2021-0247 MEDIUM
Juniper Networks Junos OS - Race Condition
CVSS 5.1
CVE-2021-0244 HIGH
Juniper Networks Junos OS - Privilege Escalation
CVSS 7.4
CVE-2021-23133 MEDIUM
Linux kernel SCTP sockets <5.12-rc8 - Privilege Escalation
CVSS 6.7
CVE-2021-0443 MEDIUM
Android - Local Information Disclosure via ScreenshotHelper Race Condition
CVSS 4.7
CVE-2021-0432 HIGH
Android 11 - Use-After-Free in StatsPullerManager.cpp via Race Condition
CVSS 7.0
CVE-2021-1806 HIGH
macOS 10.14-10.14.5 and 11.0-11.2 - Race Condition Leading to Arbitrary Code Execution with Kernel Privileges
CVSS 7.0
Details
Vulnerabilities 2,393
Exploit Likelihood Medium