CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,393 vulnerabilities with CWE-362
CVE-2018-25030 LOW
Mirmay Secure Private Browser and File Manager < 2.5 - Local Authentication Bypass via Auto Lock Race Condition
CVSS 3.3
CVE-2018-20316 HIGH
Foxit Reader <9.5 & PhantomPDF <8.3.10 & 9.x <9.5 - Buffer Overflow
CVSS 8.1
CVE-2018-20315 HIGH
Foxit Reader <9.5 & PhantomPDF <8.3.10 & 9.x <9.5 - Buffer Overflow
CVSS 8.1
CVE-2018-20314 HIGH
Foxit Reader <9.5 & PhantomPDF <8.3.10 & 9.x <9.5 - Buffer Overflow
CVSS 8.1
CVE-2018-20313 HIGH
Foxit Reader <9.5 & PhantomPDF <8.3.10/9.x - Buffer Overflow
CVSS 8.1
CVE-2018-20312 HIGH
Foxit Reader <9.5 & PhantomPDF <8.3.10 & 9.x <9.5 - Buffer Overflow
CVSS 8.1
CVE-2018-20311 HIGH
Foxit Reader <9.5 & PhantomPDF <8.3.10 & 9.x <9.5 - Buffer Overflow
CVSS 8.1
CVE-2018-20310 HIGH
Foxit Reader <9.5 & PhantomPDF <8.3.10 & 9.x <9.5 - Buffer Overflow
CVSS 8.1
CVE-2018-20309 HIGH
Foxit Reader <9.5 & PhantomPDF <8.3.10 & 9.x <9.5 - Buffer Overflow
CVSS 8.1
CVE-2018-13903 HIGH
Qualcomm Apq8053 Firmware - Race Condition
CVSS 8.1
CVE-2018-21040 HIGH
Samsung Android O(8.x) and P(9.0) - Use-After-Free via g2d Driver Race Condition
CVSS 8.1
CVE-2018-21086 HIGH
Android L(5.x) M(6.0) N(7.x) - Double Free in vnswap_init_backing_storage
CVSS 8.1
CVE-2018-21085 HIGH
Android L(5.x)-N(7.x) - Use-After-Free via Race Condition in vnswap_deinit_backing_storage
CVSS 8.1
CVE-2018-21084 HIGH
Android L(5.1) M(6.0) N(7.x) - Race Condition Read-After-Free in get_kek
CVSS 8.1
CVE-2018-20940 LOW
cPanel < 62.0.39 - Unauthenticated Root Crontab File Exposure via Backup Enablement
CVSS 3.3
CVE-2018-19572 MEDIUM
GitLab CE/E 8.17+ - Unauthorized Access
CVSS 5.9
CVE-2018-13909 HIGH
Qualcomm Snapdragon Firmware - Race Condition in Bootloader Metadata Verification
CVSS 7.0
CVE-2018-15664 HIGH
Docker through 18.06.1-ce-rc2 - Directory Traversal and Arbitrary File Write via Symlink Exchange
CVSS 7.5
CVE-2018-20836 HIGH
Linux Kernel < 4.20 - Use-After-Free via Race Condition in SAS Expander
CVSS 8.1
CVE-2018-4266 MEDIUM
Safari < 11.1.2 - Race Condition
CVSS 5.9
CVE-2018-18253 HIGH
CapMon Access Manager < 5.4.1.1005 - Race Condition in CALRunElevated.exe
CVSS 7.0
CVE-2018-18808 HIGH
TIBCO JasperReports Server <= 6.3.4; 6.4.0-6.4.3; 7.1.0 - Privilege Escalation via Domain Management Race Condition
CVSS 8.8
CVE-2018-9586 HIGH
Android 7.0-9 - Local Privilege Escalation via Package Verification Race Condition
CVSS 7.0
CVE-2018-11998 HIGH
Snapdragon Mobile/Wear <various - Out-of-bounds Access
CVSS 7.5
CVE-2018-6158 HIGH
Google Chrome <68.0.3440.75 - Heap Corruption
CVSS 7.5
Details
Vulnerabilities 2,393
Exploit Likelihood Medium