CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,398 vulnerabilities with CWE-362
CVE-2018-14625 MEDIUM
Linux Kernel - Information Disclosure via AF_VSOCK Race Condition
CVSS 5.3
CVE-2018-15499 MEDIUM
GEAR Software GEARAspiWDM 2.2.5.0 - Denial of Service via Race Condition in Memory Availability Check
CVSS 4.7
CVE-2018-15473 MEDIUM
OpenSSH < 7.7 - User Enumeration via Authentication Request Timing
CVSS 5.3
CVE-2018-8037 MEDIUM
Apache Tomcat 8.5.5-8.5.31 and 9.0.0.M9-9.0.9 - Information Disclosure via Race Condition
CVSS 5.9
CVE-2018-14329 MEDIUM
HTSlib 1.8 - Local Privilege Escalation
CVSS 4.7
CVE-2018-5873 HIGH
Linux kernel <4.11 - Use After Free
CVSS 7.0
CVE-2018-5859 HIGH
Android <2018-07-05 - Use After Free
CVSS 7.0
CVE-2018-5853 HIGH
Android <2018-05-05 - Use After Free
CVSS 7.0
CVE-2018-5832 HIGH
Android <2018-06-05 - Use After Free
CVSS 7.0
CVE-2018-12691 MEDIUM
ONOS < 1.13.0 - Network Access Control Bypass via TOCTOU Race Condition in ACL Application
CVSS 6.8
CVE-2018-8025 HIGH
Apache HBase - Privilege Escalation
CVSS 8.1
CVE-2018-12633 MEDIUM
Linux kernel <4.17.2 - Use After Free
CVSS 6.3
CVE-2018-5236 MEDIUM
Symantec Endpoint Protection - Race Condition
CVSS 5.3
CVE-2018-12029 HIGH
Phusion Passenger <5.3.2 - Privilege Escalation
CVSS 7.0
CVE-2018-1121 LOW
procps < 3.3.15 - Process Hiding via Race Condition in /proc/PID Enumeration
CVSS 3.9
CVE-2018-10850 MEDIUM
389 Directory Server < 1.4.0.10 - Denial of Service via Persistent Search Race Condition
CVSS 5.9
CVE-2018-3759 LOW
private_address_check < 0.5.0 - Time-of-Check Time-of-Use Race Condition
CVSS 3.7
CVE-2018-5849 HIGH
Android QTEECOM Driver - Use-After-Free via Race Condition in TA Loading
CVSS 7.0
CVE-2018-5814 HIGH
Linux Kernel <4.16.11-4.4.133 - Use After Free
CVSS 7.0
CVE-2018-12232 MEDIUM
Linux kernel <4.17.1 - Use After Free
CVSS 5.9
CVE-2018-4230 HIGH
macOS < 10.13.5 - Use-After-Free in NVIDIA Graphics Drivers via SetAppSupportBits Race Condition
CVSS 7.0
CVE-2018-4228 HIGH
macOS < 10.13.5 - Race Condition in IOFireWireAVC
CVSS 7.0
CVE-2018-4192 HIGH
Safari < 11.1.1 - Remote Code Execution via WebKit Race Condition
CVSS 7.5
CVE-2018-5845 HIGH
Android - Use-After-Free via Race Condition in drm_atomic_nonblocking_commit()
CVSS 7.0
CVE-2018-6236 HIGH
Trend Micro Antivirus+ < 12.0 - Privilege Escalation via tmusa Driver IOCTL
CVSS 7.0
Details
Vulnerabilities 2,398
Exploit Likelihood Medium