CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,400 vulnerabilities with CWE-362
CVE-2012-5507
Zope < 2.13.19 and Plone < 4.2.3 - Remote Password Exposure via Timing Attack
CVE-2012-0426
SUSE Linux Enterprise for SAP Applications 11 SP2 - Info Disclosure
CVE-2012-5415
Cisco Adaptive Security Appliance - Denial of Service via Hash Lookup Race Condition
CVE-2012-5660
Automatic Bug Reporting Tool < 2.0.9 - Privilege Escalation via Symlink Attack
CVE-2012-6095
ProFTPD < 1.3.5rc1 - Race Condition via MKD/XMKD Symlink Attack
CVE-2012-4508
Linux Kernel <3.4.16 - Info Disclosure
CVE-2012-5119
Google Chrome < 23.0.1271.64 - Denial of Service via Pepper Buffer Race Condition
CVE-2012-3748
Safari < 6.0.1 - Remote Code Execution via JavaScript Array Race Condition
CVE-2012-5108
Google Chrome < 22.0.1229.92 - Remote Code Execution via Audio Device Race Condition
CVE-2012-3511
Linux Kernel < 3.4.5 - Denial of Service via Race Condition in madvise_remove
CVE-2012-3552 MEDIUM
Linux Kernel < 3.0 - Denial of Service via Race Condition in IP Socket Options Handling
CVSS 5.9
CVE-2012-3500
devscripts < 2.12.2 - Arbitrary File Modification via Symlink Attack on Temporary Files
CVE-2012-2880
Google Chrome <22.0.1229.79 - DoS
CVE-2012-2868
Google Chrome <21.0.1180.89 - DoS
CVE-2012-3487
Tunnelblick < 3.3beta20 - Local Process Termination via PID Race Condition
CVE-2012-3483
Tunnelblick < 3.3beta20 - Local Privilege Escalation via Race Condition in runScript
CVE-2012-2373
Linux kernel < 3.4.5 - Denial of Service via PMD Race Condition
CVE-2012-3386
GNU Automake < 1.11.6 and 1.12.x < 1.12.2 - Local Race Condition via World-Writable Extraction Directory
CVE-2012-1338
Cisco IOS 15.0-15.1 on Catalyst 3560/3750 - Authenticated DoS via Rapid Local Web Auth
CVE-2012-3868
ISC BIND 9.9.x - Denial of Service via TCP Query Race Condition
CVE-2012-2737
AccountsService <0.6.22 - Info Disclosure
CVE-2012-1174
systemd - Unauthenticated Arbitrary File Deletion via Symlink Attack in rm_rf_children
CVE-2012-3063
Cisco ACE <A4(2.3) & A5(1.1) - Privilege Escalation
CVE-2012-1868
Windows XP SP3 - Local Privilege Escalation via Win32k.sys Thread Creation Race Condition
CVE-2012-0656
Apple Mac OS X 10.7.x <10.7.4 - Privilege Escalation
Details
Vulnerabilities 2,400
Exploit Likelihood Medium