CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,400 vulnerabilities with CWE-362
CVE-2017-2533 HIGH
macOS < 10.12.5 - Race Condition in DiskArbitration
CVSS 7.0
CVE-2017-2501 HIGH
iPhone OS < 10.3.2, macOS < 10.12.5, tvOS < 10.2.1, watchOS < 3.2.2 - Race Condition in Kernel
CVSS 7.0
CVE-2017-8244 HIGH
Android - Race Condition in MSMVIDC DebugFS Driver
CVSS 7.0
CVE-2017-0343 HIGH
NVIDIA GPU Display Driver - Denial of Service or Privilege Escalation via Race Condition in Kernel Mode Layer
CVSS 7.0
CVE-2017-8342 HIGH
Radicale < 1.1.2 and 2.x < 2.0.0rc2 - Timing Attack via htpasswd Authentication
CVSS 8.1
CVE-2017-5035 HIGH
Google Chrome <57.0.2987.98 - Info Disclosure
CVSS 8.1
CVE-2017-6615 MEDIUM
Cisco IOS XE 3.16 - Authenticated Denial of Service via SNMP Read Request Race Condition
CVSS 6.3
CVE-2017-0462 HIGH
Linux Kernel - Race Condition in Qualcomm Seemp Driver
CVSS 7.0
CVE-2017-7572 HIGH
Back In Time <1.1.18 - Privilege Escalation
CVSS 8.1
CVE-2017-2478 HIGH
iPhone OS < 10.3, macOS < 10.12.4, tvOS < 10.2, watchOS < 3.2 - Race Condition in Kernel
CVSS 7.0
CVE-2017-2456 HIGH
iPhone OS < 10.3, macOS < 10.12.4, tvOS < 10.2, watchOS < 3.2 - Kernel Race Condition
CVSS 7.0
CVE-2017-2421 HIGH
macOS < 10.12.4 - Race Condition in AppleGraphicsPowerManagement
CVSS 7.8
CVE-2017-5899 HIGH
s-nail < 14.8.5 - Path Traversal via randstr Argument
CVSS 7.0
CVE-2017-6874 HIGH
Linux Kernel 4.9-4.9.15 - Use-After-Free via ucounts Race Condition
CVSS 7.0
CVE-2017-2636 HIGH
Linux Kernel <= 4.10.1 - Race Condition in HDLC Line Discipline
CVSS 7.0
CVE-2017-6408 HIGH
Veritas NetBackup < 8.0 and NetBackup Appliance < 3.0 - Local Privilege Escalation via pbx_exchange Race Condition
CVSS 7.0
CVE-2017-6346 HIGH
Linux Kernel < 3.2.87 - Use-After-Free via PACKET_FANOUT Setsockopt Race Condition
CVSS 7.0
CVE-2017-6001 HIGH
Linux Kernel 3.18.54-3.18.92 - Race Condition in perf_event_open
CVSS 7.0
CVE-2017-5986 MEDIUM
Linux Kernel < 4.9.11 - Denial of Service via SCTP Association Peeling Race Condition
CVSS 5.5
CVE-2016-15036 MEDIUM
Deis Workflow Manager <2.3.3 - Race Condition
CVSS 4.6
CVE-2016-20015 HIGH
SmokePing <2.7.3-r1 - Privilege Escalation
CVSS 7.5
CVE-2016-11030 HIGH
Android KK(4.4) L(5.0/5.1) M(6.0) - Heap-Based Buffer Overflow via MAX86902 Sensor Driver Race Condition
CVSS 8.1
CVE-2016-1000236 MEDIUM
Node-cookie-signature <1.0.6 - Info Disclosure
CVSS 4.4
CVE-2016-10906 HIGH
Linux Kernel < 4.5 - Use-After-Free via Race Condition in arc_emac_tx and arc_emac_tx_clean
CVSS 7.0
CVE-2016-10798 MEDIUM
cPanel 55.9999.61-56.0.27 - Race Condition via rearrangeacct
CVSS 6.8
Details
Vulnerabilities 2,400
Exploit Likelihood Medium