CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,393 vulnerabilities with CWE-362
CVE-2020-9329 MEDIUM
Gogs <= 0.11.91 - Race Condition in Repository Creation Policy Enforcement
CVSS 5.9
CVE-2020-3163 MEDIUM
Cisco Unified Contact Center Enterprise - DoS
CVSS 5.9
CVE-2020-1814 MEDIUM
Huawei NIP6800 <V500R005C00 - Privilege Escalation
CVSS 5.3
CVE-2020-0030 HIGH
Android - Use-After-Free via Race Condition in binder_thread_release
CVSS 7.0
CVE-2020-6388 HIGH
Google Chrome <80.0.3987.87 - Heap Corruption
CVSS 8.8
CVE-2020-3941 HIGH
VMware Tools <11 - Privilege Escalation
CVSS 7.0
CVE-2020-0008 MEDIUM
Android -8.0,-8.1,-9,-10 - Info Disclosure
CVSS 4.7
CVE-2019-14711 HIGH
Verifone MX900 - Privilege Escalation
CVSS 7.0
CVE-2019-15879 HIGH
FreeBSD <12.1-STABLE r356908, 11.3-STABLE r356908 - Use After Free
CVSS 7.4
CVE-2019-14898 HIGH
Linux Kernel < 5.0.10 - Improper Locking in mmget_not_zero or get_task_mm
CVSS 7.0
CVE-2019-14070 HIGH
Snapdragon Auto- Snapdragon Compute - Use After Free
CVSS 7.0
CVE-2019-20568 HIGH
Android O(8.x) and P(9.0) - Use-After-Free via Race Condition
CVSS 8.1
CVE-2019-14072 HIGH
Qualcomm Snapdragon Firmware - Use-After-Free via Race Condition in Sparse Memory Management
CVSS 7.0
CVE-2019-11215 HIGH
Combodo iTop 2.2.0-2.3.9, 2.4.1-2.5.9 - Arbitrary Code Execution via Configuration File Race Condition
CVSS 8.1
CVE-2019-18567 MEDIUM
Bromium client <4.1.7.1 - Memory Corruption
CVSS 6.3
CVE-2019-3016 MEDIUM
Linux Kernel >= 4.16 - Unauthorized Memory Read via PV TLB Race Condition
CVSS 6.2
CVE-2019-18932 HIGH
Squid Analysis Report Generator <2.3.11 - Privilege Escalation
CVSS 7.0
CVE-2019-20384 MEDIUM
Gentoo Portage < 2.3.84 - Race Condition in Plugin Directory Ownership
CVSS 5.5
CVE-2019-19278 MEDIUM
SINAMICS PERFECT HARMONY GH180 Drives - Unauthenticated RCE
CVSS 6.8
CVE-2019-17021 MEDIUM
Firefox < 72.0 and Firefox ESR < 68.4 - Heap Address Disclosure via Content Process Initialization Race Condition
CVSS 5.3
CVE-2019-17011 HIGH
Firefox < 71.0 and Firefox ESR < 68.3 - Use-After-Free via DocShell Race Condition
CVSS 7.5
CVE-2019-17010 HIGH
Firefox <71.0, ESR <68.3, Thunderbird <68.3 - Use-After-Free via Race Condition
CVSS 7.5
CVE-2019-11761 MEDIUM
Firefox < 70, Thunderbird < 68.2, Firefox ESR < 68.2 - CSRF
CVSS 5.4
CVE-2019-11090 MEDIUM
Intel Platform Trust Technology Firmware < 11.8.70 - Information Disclosure via Timing Conditions
CVSS 5.9
CVE-2019-8757 LOW
macOS < 10.15 - Unprotected User Data Exposure via Race Condition in Preferences Handling
CVSS 2.5
Details
Vulnerabilities 2,393
Exploit Likelihood Medium