CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,393 vulnerabilities with CWE-362
CVE-2019-5840 MEDIUM
Google Chrome < 75.0.3770.80 - Security UI Bypass in Popup Blocker
CVSS 4.3
CVE-2019-2008 HIGH
Android -8.0, -8.1, -9 - Memory Corruption
CVSS 7.5
CVE-2019-2006 CRITICAL
Android 9 - Use-After-Free in HalDeathHandlerHidl.cpp serviceDied
CVSS 9.8
CVE-2019-2095 HIGH
Android - Use-After-Free in SkPixelRef.cpp via Race Condition
CVSS 7.0
CVE-2019-5216 HIGH
Huawei Honor V10 <9.0.0.156(C00E156R2P14T8) - Use After Free
CVSS 7.0
CVE-2019-12450 CRITICAL
GLib 2.15.0-2.61.1 - Unrestricted File Permissions During Copy Operation
CVSS 9.8
CVE-2019-12448 HIGH
gvfs 1.29.4-1.41.2 - Race Condition in Admin Backend
CVSS 8.1
CVE-2019-10143 HIGH
Freeradius <3.0.19 - Privilege Escalation
CVSS 7.0
CVE-2019-5796 HIGH
Google Chrome < 73.0.3683.75 - Data Race in Extensions Guest View
CVSS 7.5
CVE-2019-0114 MEDIUM
Intel Graphics Driver - Denial of Service via Race Condition
CVSS 4.7
CVE-2019-8978 HIGH
Ellucian Banner Enterprise Identity Services - Race Condition
CVSS 8.1
CVE-2019-11815 HIGH
Linux kernel <5.0.8 - Use After Free
CVSS 8.1
CVE-2019-11675 HIGH
Groonga-httpd 6.1.5-1 - Privilege Escalation
CVSS 7.0
CVE-2019-11486 HIGH
Linux Kernel <5.0.8 - Info Disclosure
CVSS 7.0
CVE-2019-11191 LOW
Linux Kernel < 5.0.7 - Race Condition in AOUT Binary Loader
CVSS 2.5
CVE-2019-11190 MEDIUM
Linux Kernel < 4.8 - Race Condition in ASLR Bypass via /proc/pid/stat
CVSS 4.7
CVE-2019-3837 MEDIUM
Linux Kernel 2.6.32 - Use-After-Free in net_dma tcp_recvmsg()
CVSS 6.1
CVE-2019-0217 HIGH
Apache HTTP Server < 2.4.38 - Authentication Bypass via Race Condition in mod_auth_digest
CVSS 7.5
CVE-2019-9710 HIGH
webargs < 5.1.3 - Race Condition in JSON Body Parsing Cache
CVSS 8.1
CVE-2019-1992 HIGH
Android 7.0-9 - Use-After-Free via Race Condition in bta_hl_sdp_query_results
CVSS 7.5
CVE-2019-6974 HIGH
Linux kernel <4.20.8 - Use After Free
CVSS 8.1
CVE-2019-7718 HIGH
Metinfo 6.0.0-6.1.2 - Authenticated Remote Code Execution via Database Backup Race Condition
CVSS 8.1
CVE-2019-3461 HIGH
Debian tmpreaper 1.6.13+nmu1 - Local Privilege Escalation via Race Condition in Mount Rename
CVSS 7.0
CVE-2019-6133 MEDIUM
polkit 0.115 - Race Condition via Fork-Based Authorization Bypass
CVSS 6.7
CVE-2018-9461 HIGH
Android - Local Privilege Escalation via ShareIntentActivity Race Condition
CVSS 7.0
Details
Vulnerabilities 2,393
Exploit Likelihood Medium