CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,398 vulnerabilities with CWE-362
CVE-2017-11025 HIGH
Android for MSM - Memory Corruption via Race Condition in audio_effects_shared_ioctl()
CVSS 7.0
CVE-2017-2898 HIGH
Circle with Disney Firmware - Arbitrary Code Execution via Firmware Update Signature Verification Race Condition
CVSS 7.5
CVE-2017-16001 HIGH
HashiCorp Vagrant VMware Fusion Plugin 5.0.1 - Local Privilege Escalation via Update Process Race Condition
CVSS 7.8
CVE-2017-15884 HIGH
HashiCorp Vagrant VMware Fusion 5.0.0 - Local Privilege Escalation via Plugin Update Race Condition
CVSS 7.0
CVE-2017-5068 HIGH
Google Chrome <58.0.3029.96 - Remote Code Execution
CVSS 7.5
CVE-2017-5061 MEDIUM
Google Chrome <58.0.3029.81 - Info Disclosure
CVSS 5.3
CVE-2017-7115 HIGH
iPhone OS < 10.3.3 and tvOS < 10.2.2 - Remote Code Execution or Denial of Service via Wi-Fi Race Condition
CVSS 8.1
CVE-2017-15649 HIGH
Linux Kernel < 4.13.6 - Use-After-Free via Packet Fanout Race Condition
CVSS 7.8
CVE-2017-15588 HIGH
Xen through 4.9.x - Race Condition Leading to Arbitrary Code Execution via Stale TLB Entry
CVSS 7.8
CVE-2017-15265 HIGH
Linux Kernel < 4.13.8 - Use-After-Free via ALSA Subsystem ioctl Calls
CVSS 7.0
CVE-2017-11823 MEDIUM
Microsoft Windows <10.0 - Privilege Escalation
CVSS 6.7
CVE-2017-9697 HIGH
Android - Use-After-Free via Race Condition in diag_dbgfs_read_table
CVSS 7.0
CVE-2017-15038 MEDIUM
QEMU < 2.9.1 - Information Disclosure via v9fs_xattrwalk Race Condition
CVSS 5.6
CVE-2017-15037 HIGH
FreeBSD < 11.1 - Out-of-bounds Read via smb_strdupin Race Condition
CVSS 8.1
CVE-2017-1000112 HIGH
Linux Kernel UDP Fragmentation Offset (UFO) Privilege Escalation
CVSS 7.0
CVE-2017-14955 MEDIUM
Checkmk - Information Disclosure
CVSS 5.9
CVE-2017-14748 MEDIUM
Blizzard Overwatch 1.15.0.2 - Authenticated Denial of Service via Competitive Match Loading Race Condition
CVSS 5.3
CVE-2017-1346 LOW
IBM Business Process Manager <8.6 - Info Disclosure
CVSS 2.5
CVE-2017-9677 HIGH
Android < 8.0 - Buffer Overflow via Race Condition in msm_compr_ioctl_shared
CVSS 7.8
CVE-2017-9676 MEDIUM
Android < 8.0 - Exposure of Sensitive Information via Race Condition
CVSS 4.7
CVE-2017-8281 MEDIUM
Android < 8.0 - Use-After-Free in DCI Event Status Query
CVSS 4.7
CVE-2017-8280 HIGH
Android < 8.0 - Memory Corruption via WLAN Calibration Data Race Condition
CVSS 7.0
CVE-2017-14483 MEDIUM
Gentoo dev-python/flower <0.9.1-r1 - Privilege Escalation
CVSS 5.5
CVE-2017-0161 HIGH
Windows NetBT Session Services - Remote Code Execution via Race Condition
CVSS 8.1
CVE-2017-14317 MEDIUM
Xen < 4.9.0 - Denial of Service via cxenstored Double-Free Race Condition
CVSS 5.6
Details
Vulnerabilities 2,398
Exploit Likelihood Medium