CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,393 vulnerabilities with CWE-362
CVE-2021-25158 MEDIUM
Aruba Instant <8.5.0.11 - Info Disclosure
CVSS 5.9
CVE-2021-29265 MEDIUM
Linux Kernel < 5.11.7 - Denial of Service via Race Condition in USB/IP Stub Device Status Update
CVSS 4.7
CVE-2021-20197 MEDIUM
GNU binutils < 2.35 - Race Condition in ar, objcopy, strip, ranlib
CVSS 6.3
CVE-2021-28964 MEDIUM
Linux Kernel < 5.11.8 - Denial of Service via Race Condition in Btrfs get_old_root
CVSS 4.7
CVE-2021-26569 CRITICAL
Synology DiskStation Manager < 6.2.3-25426-3 - Remote Code Execution via Race Condition in iscsi_snapshot_comm_core
CVSS 9.8
CVE-2021-20261 MEDIUM
Linux Kernel - Race Condition in Floppy Disk Drive Controller Driver
CVSS 6.4
CVE-2021-0387 MEDIUM
Android 11 - Use-After-Free in QuotaUtils.cpp via Race Condition
CVSS 6.4
CVE-2021-21166 HIGH KEV
Google Chrome <89.0.4389.72 - Heap Corruption
CVSS 8.8
CVE-2021-21165 HIGH
Google Chrome <89.0.4389.72 - Heap Corruption
CVSS 8.8
CVE-2021-0401 MEDIUM
Android 10-11 - Local Privilege Escalation via Race Condition in vow
CVSS 6.4
CVE-2021-0367 MEDIUM
Android 10-11 - Race Condition in vpu
CVSS 6.4
CVE-2021-0366 MEDIUM
Android 10-11 - Race Condition in vpu Leading to Memory Corruption
CVSS 6.4
CVE-2021-22974 HIGH
F5 BIG-IP 13.1.0-13.1.3.5 - Authenticated Privilege Escalation via iControl REST Race Condition
CVSS 7.5
CVE-2021-21117 HIGH
Google Chrome <88.0.4324.96 - Privilege Escalation
CVSS 7.8
CVE-2021-3348 HIGH
Linux Kernel < 5.10.12 - Use-After-Free in nbd_add_socket
CVSS 7.0
CVE-2021-0320 MEDIUM
Android -10, Android-11 - Info Disclosure
CVSS 4.7
CVE-2021-0303 HIGH
Android 11 - Use-After-Free via Race Condition in StreamSetObserver
CVSS 7.0
CVE-2021-1061 MEDIUM
NVIDIA vGPU <8.6-11.3 - Info Disclosure
CVSS 6.3
CVE-2020-19824 HIGH
mpv 0.29.1 - Remote Code Execution via ao_c Parameter
CVSS 7.0
CVE-2020-36558 MEDIUM
Linux Kernel < 5.5.7 - NULL Pointer Dereference via VT_RESIZEX Race Condition
CVSS 5.1
CVE-2020-36557 MEDIUM
Linux Kernel < 5.6.2 - Use-After-Free via VT_DISALLOCATE ioctl Race Condition
CVSS 5.1
CVE-2020-25719 HIGH
Samba 4.0.0-4.13.14 - Improper Authentication via Kerberos PAC Handling
CVSS 7.2
CVE-2020-35216 MEDIUM
Atomix 3.1.5 - Denial of Service via False Member Down Event Messages
CVSS 5.9
CVE-2020-12951 HIGH
ASP firmware - Privilege Escalation
CVSS 7.0
CVE-2020-29622 HIGH
Security Update 2021-005 Catalina - RCE
CVSS 7.5
Details
Vulnerabilities 2,393
Exploit Likelihood Medium