CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,393 vulnerabilities with CWE-362
CVE-2019-8606 HIGH
macOS < 10.14.5 - Unsigned Kernel Extension Loading via Symlink Validation Issue
CVSS 7.0
CVE-2019-8565 HIGH
Mac OS X Feedback Assistant Race Condition
CVSS 7.0
CVE-2019-6236 HIGH
iCloud for Windows < 7.11 - Arbitrary Code Execution via Race Condition in Installer
CVSS 7.5
CVE-2019-6232 HIGH
iCloud for Windows < 7.11 - Arbitrary Code Execution via Race Condition in iTunes Installer
CVSS 7.5
CVE-2019-16779 MEDIUM
RubyGem excon <0.71.0 - Info Disclosure
CVSS 5.8
CVE-2019-18827 MEDIUM
Barco ClickShare Button R9861500D01 <1.9.0 - Info Disclosure
CVSS 5.9
CVE-2019-19580 MEDIUM
Xen < 4.12.1 - Privilege Escalation via Pagetable Promotion/Demotion Race Condition
CVSS 6.6
CVE-2019-2219 MEDIUM
Android 11 - Local Privilege Escalation via NotificationManagerService Permission Bypass
CVSS 4.7
CVE-2019-19537 MEDIUM
Linux kernel <5.2.10 - Privilege Escalation
CVSS 4.2
CVE-2019-19017 HIGH
TitanHQ WebTitan <5.18 - Privilege Escalation
CVSS 8.1
CVE-2019-2213 HIGH
Android - Use-After-Free in binder_free_transaction
CVSS 7.4
CVE-2019-5228 HIGH
Honor V20 <9.1.0.193(C00E190R1P21) - Code Injection
CVSS 7.8
CVE-2019-1416 HIGH
Windows 10 and Windows Server 2016/2019 - Elevation of Privilege via Race Condition in Windows Subsystem for Linux
CVSS 7.0
CVE-2019-10529 HIGH
Qualcomm Snapdragon Firmware - Use-After-Free via Race Condition in set_page_dirty()
CVSS 8.1
CVE-2019-8232 MEDIUM
Magento < 1.9.4.3, < 1.14.4.3, 2.2.0-2.2.9, < 2.3.3 - Remote Code Execution via Import Race Condition
CVSS 6.6
CVE-2019-18684 HIGH
Sudo <1.8.29 - Privilege Escalation
CVSS 7.0
CVE-2019-18683 HIGH
Linux kernel <5.3.8 - Privilege Escalation
CVSS 7.0
CVE-2019-18421 HIGH
Xen < 4.12.1 - Privilege Escalation via Pagetable Promotion/Demotion Race Condition
CVSS 7.5
CVE-2019-8162 HIGH
Adobe Acrobat and Reader DC < 15.006.30504, 15.008.20082-19.021.20047 - Arbitrary Code Execution via Race Condition
CVSS 8.1
CVE-2019-14810 MEDIUM
Arista EOS 4.19-4.19.12M, 4.20-4.20.14M, 4.21.0F-4.21.7.1M, 4.22-4.22.1F DoS via LDP Race Condition
CVSS 5.9
CVE-2019-6471 MEDIUM
BIND 9.11.0-9.11.7, 9.12.0-9.12.4-P1, 9.14.0-9.14.2 - Denial of Service via Race Condition in Dispatch
CVSS 5.9
CVE-2019-17342 HIGH
Xen < 4.11.2 - Denial of Service and Privilege Escalation via XENMEM_exchange Race Condition
CVSS 7.0
CVE-2019-17341 HIGH
Xen < 4.11.2 - Denial of Service and Privilege Escalation via PCI Device Page-Writability Race Condition
CVSS 7.8
CVE-2019-2284 HIGH
Qualcomm Snapdragon - Use After Free
CVSS 7.0
CVE-2019-9375 MEDIUM
Android 10 - Local Privilege Escalation via Race Condition in hostapd
CVSS 6.4
Details
Vulnerabilities 2,393
Exploit Likelihood Medium