CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,400 vulnerabilities with CWE-362
CVE-2016-8655 HIGH
AF_PACKET chocobo_root Privilege Escalation
CVSS 7.8
CVE-2016-7916 MEDIUM
Linux Kernel < 4.5.3 - Information Disclosure via /proc/*/environ Race Condition
CVSS 5.5
CVE-2016-7911 HIGH
Linux Kernel < 4.6.6 - Race Condition in get_task_ioprio Function
CVSS 7.8
CVE-2016-5195 HIGH KEV
Linux Kernel 2.x-4.x < 4.8.3 - Local Privilege Escalation via Dirty COW Race Condition
CVSS 7.0
CVE-2016-3914 HIGH
Android <4.4.4, <5.0.2, <5.1.1, <2016-10-01 - Privilege Escalation
CVSS 7.8
CVE-2016-7777 MEDIUM
Xen < 4.7.0 - Local FPU/MMX/XMM Register State Leak via Instruction Modification
CVSS 6.3
CVE-2016-7098 HIGH
wget < 1.17 - Race Condition in Recursive/Mirroring Mode
CVSS 8.1
CVE-2016-0930 CRITICAL
Pivotal Cloud Foundry (PCF) Ops Manager <1.6.19 and 1.7.x <1.7.10 -...
CVSS 9.8
CVE-2016-6516 HIGH
Linux Kernel <4.7 - Privilege Escalation
CVSS 7.4
CVE-2016-6480 MEDIUM
Linux Kernel < 4.7 - Denial of Service via Race Condition in ioctl_send_fib
CVSS 5.1
CVE-2016-6156 MEDIUM
Linux Kernel < 4.6.6 - Denial of Service via Double Fetch in ec_device_ioctl_xcmd
CVSS 5.1
CVE-2016-6136 MEDIUM
Linux kernel <4.7 - Info Disclosure
CVSS 4.7
CVE-2016-4583 LOW
WebKit - Same Origin Policy Bypass via SVG Timing Attack
CVSS 3.1
CVE-2016-4247 MEDIUM
Adobe Flash Player <22.0.0.209 - Info Disclosure
CVSS 5.3
CVE-2016-3258 MEDIUM
Microsoft Windows Security Feature Bypass via Object Manager Race Condition
CVSS 4.7
CVE-2016-3760 HIGH
Android <5.0.2, <5.1.1, <6 - Privilege Escalation
CVSS 7.5
CVE-2016-3744 HIGH
Android <4.4.4, <5.0.2, <5.1.1, <2016-07-01 - Buffer Overflow
CVSS 7.5
CVE-2016-4955 MEDIUM
NTP 4.x < 4.2.8p8 - Denial of Service via Spoofed Crypto-NAK or Incorrect MAC Packet
CVSS 5.9
CVE-2016-4954 HIGH
ntp 4.x < 4.2.8p8 - Denial of Service via Spoofed Packet Processing
CVSS 7.5
CVE-2016-6130 MEDIUM
Linux kernel <4.6 - Info Disclosure
CVSS 4.7
CVE-2016-4309 HIGH
Symphony CMS 2.6.7 - Info Disclosure
CVSS 7.5
CVE-2016-1807 MEDIUM
Apple <9.3.2, <10.11.5, <9.2.1, <2.2.1 - Info Disclosure
CVSS 5.1
CVE-2016-1670 MEDIUM
Google Chrome < 50.0.2661.102 - Race Condition in ResourceDispatcherHostImpl
CVSS 5.3
CVE-2016-2812 HIGH
Firefox < 45.0.2 - Remote Code Execution via Service Worker Race Condition
CVSS 7.5
CVE-2016-2547 MEDIUM
Linux Kernel < 4.4 - Denial of Service via Race Condition in Timer Ioctl
CVSS 5.1
Details
Vulnerabilities 2,400
Exploit Likelihood Medium