CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,393 vulnerabilities with CWE-362
CVE-2020-0268 MEDIUM
Android 11 - Use-After-Free via NFC Race Condition
CVSS 6.4
CVE-2020-0373 MEDIUM
Android 11 - Out-of-bounds Read in SoundTriggerHwService
CVSS 4.7
CVE-2020-0428 MEDIUM
Android - Use-After-Free via Race Condition in CamX
CVSS 6.4
CVE-2020-8342 HIGH
Lenovo System Update <5.07.0106 - Privilege Escalation
CVSS 7.3
CVE-2020-25285 MEDIUM
Linux Kernel < 5.8.8 - Race Condition in hugetlb sysctl Handlers
CVSS 6.4
CVE-2020-24655 MEDIUM
Twilio Authy <24.3.7 - Privilege Escalation
CVSS 5.1
CVE-2020-16602 HIGH
Razer Chroma SDK < 3.12.17 - Remote Code Execution via Race Condition in App Registration
CVSS 8.1
CVE-2020-15309 HIGH
wolfssl < 4.5.0 - Cache-Timing Attack via Public Key Operations
CVSS 7.0
CVE-2020-8680 HIGH
Intel(R) Graphics Drivers <15.40.45.5126 - Privilege Escalation
CVSS 7.0
CVE-2020-0554 HIGH
Intel Wireless Bluetooth Firmware < 21.70 - Privilege Escalation via Race Condition
CVSS 7.0
CVE-2020-15707 MEDIUM
GRUB2 < 2.04 - Integer Overflow and Heap-Based Buffer Overflow in efilinux initrd Handling
CVSS 5.7
CVE-2020-15706 MEDIUM
GRUB2 < 2.04 - Use-After-Free via Function Redefinition Race Condition
CVSS 6.4
CVE-2020-0305 MEDIUM
Android - Use-After-Free via Race Condition in cdev_get
CVSS 6.4
CVE-2020-1645 HIGH
Juniper Junos OS 17.3-19.4 - Denial of Service via DNS Filtering Packet Stream
CVSS 8.3
CVE-2020-1641 MEDIUM
Junos OS - Denial of Service via LLDP Packet Race Condition
CVSS 6.5
CVE-2020-15586 MEDIUM
GO < 1.13.13 - Race Condition
CVSS 5.9
CVE-2020-12420 HIGH
Firefox ESR < 68.10, Firefox < 78, Thunderbird < 68.10.0 - Use Afte...
CVSS 8.8
CVE-2020-12416 HIGH
Firefox < 78.0 - Use-After-Free in VideoStreamEncoder
CVSS 8.8
CVE-2020-12405 MEDIUM
Thunderbird <68.9.0-Firefox <77-Firefox ESR <68.9 - RCE
CVSS 5.3
CVE-2020-7457 HIGH
FreeBSD ip6_setpktopt Use-After-Free Privilege Escalation
CVSS 8.1
CVE-2020-15567 HIGH
Xen < 4.13.1 - Race Condition via Non-Atomic EPT PTE Modification
CVSS 7.8
CVE-2020-1839 MEDIUM
HUAWEI Mate 30 <10.1.0.150(C00E136R5P3 - Code Execution
CVSS 6.3
CVE-2020-15530 HIGH
Valve Steam Client 2.10.91.91 - Privilege Escalation via Weak Directory Permissions
CVSS 7.8
CVE-2020-4387 MEDIUM
IBM DB2 9.7, 10.1, 10.5, 11.1, 11.5 - Sensitive Information Exposure via Symbolic Link Race Condition
CVSS 4.7
CVE-2020-4386 MEDIUM
IBM DB2 9.7, 10.1, 10.5, 11.1, 11.5 - Sensitive Information Exposure via Symbolic Link Race Condition
CVSS 4.7
Details
Vulnerabilities 2,393
Exploit Likelihood Medium