CWE-362
Medium likelihoodConcurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
2,400 vulnerabilities with CWE-362
CVE-2016-10741
MEDIUM
Linux Kernel < 4.9.3 - Denial of Service via Race Condition in XFS Direct and Memory-Mapped I/O
CVSS 4.7
CVE-2016-9077
HIGH
Firefox < 50.0 - Timing Attack via feDisplacementMap Filter on Cross-Origin Images
CVSS 7.0
CVE-2016-10538
LOW
node-cli < 1.0.0 - Path Traversal via Insecure Lock and Log File Handling
CVSS 3.5
CVE-2016-9038
HIGH
Invincea-X <6.1.3-24058 - Privilege Escalation
CVSS 7.8
CVE-2016-10439
HIGH
Qualcomm Snapdragon SD 425/430/450/625/650/652/820/820A Firmware - Race Condition in Bulletin Board Read Syscall
CVSS 8.1
CVE-2016-10435
HIGH
Qualcomm MDM9206 and related firmware - Race Condition in QTEE Syscall Handlers
CVSS 8.1
CVE-2016-10433
HIGH
Qualcomm Snapdragon Firmware - Memory Corruption via SSD Image Decryption TOCTOU
CVSS 8.1
CVE-2016-10432
HIGH
Qualcomm Snapdragon Firmware - Race Condition via tQSEE System Call
CVSS 8.1
CVE-2016-10417
HIGH
Qualcomm MDM9206 and Snapdragon Firmware - TOCTOU via Improper Access Control in QTEE
CVSS 8.1
CVE-2016-10409
HIGH
Qualcomm Snapdragon SD 425/430/450/625/650/52/820/820A/835 - Race Condition in RPMB
CVSS 8.1
CVE-2016-10383
HIGH
Qualcomm Android - Race Condition in Secure UI
CVSS 8.1
CVE-2016-4984
MEDIUM
openldap-servers - Race Condition in TLS Certificate Generation
CVSS 4.7
CVE-2016-4982
MEDIUM
authd - Local Key Exposure via Race Condition in /etc/ident.key
CVSS 4.7
CVE-2016-0764
MEDIUM
Red Hat Network Manager <1.0.12 - Info Disclosure
CVSS 6.2
CVE-2016-10297
HIGH
Android TrustZone - Time-of-Check Time-of-Use Race Condition
CVSS 7.0
CVE-2016-10242
HIGH
Android - Time-of-Check Time-of-Use Race Condition in Secure File System
CVSS 7.0
CVE-2016-9256
HIGH
F5 BIG-IP 12.1.0-12.1.2 - Info Disclosure
CVSS 7.5
CVE-2016-3106
MEDIUM
Pulp < 2.8.3 - Race Condition in CA Key Generation Temporary Directory
CVSS 5.3
CVE-2016-10200
HIGH
Linux Kernel < 4.8.14 - Use-After-Free via L2TPv3 IP Encapsulation Race Condition
CVSS 7.0
CVE-2016-9962
MEDIUM
Docker 1.11.0-1.12.5 and runC < 1.0.0-rc3 - Container Escape via Process Tracing Race Condition
CVSS 6.4
CVE-2016-9381
HIGH
QEMU < 2.7.1 - Race Condition via Shared Ring Data Manipulation
CVSS 7.5
CVE-2016-10027
MEDIUM
Smack <4.1.9 - Privilege Escalation
CVSS 5.9
CVE-2016-9806
HIGH
Linux Kernel < 3.12.62 - Race Condition in netlink_dump Function
CVSS 7.8
CVE-2016-9794
HIGH
Linux Kernel < 3.2.85 - Use-After-Free via ALSA SNDRV_PCM_TRIGGER_START Command
CVSS 7.8
CVE-2016-6663
HIGH
Oracle MySQL <5.5.52, 5.6.x <5.6.33, 5.7.x <5.7.15, and 8.x <8.0.1 - Privilege Escalation
CVSS 7.0
Details
Vulnerabilities
2,400
Exploit Likelihood
Medium