CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,400 vulnerabilities with CWE-362
CVE-2010-5167
Norman Security Suite PRO 8.0 - Privilege Escalation
CVE-2010-5166
McAfee Total Protection 2010 10.0.580 - Privilege Escalation
CVE-2010-5165
Malware Defender 2.6.0 - Privilege Escalation
CVE-2010-5164 MEDIUM
KingSoft Personal Firewall 9 Plus 2009.05.07.70 - Local Race Condition via User-Space Memory Changes
CVSS 5.3
CVE-2010-5163
Kaspersky Internet Security 2010 9.0.0.736 - Privilege Escalation
CVE-2010-5162
G DATA TotalCare 2010 - Privilege Escalation
CVE-2010-5161
F-Secure Internet Security 2010 - Privilege Escalation
CVE-2010-5160 MEDIUM
ESET Smart Security <4.2.35.3 - Privilege Escalation
CVSS 4.5
CVE-2010-5159 HIGH
Dr.Web Security Space Pro 6.0.0.03100 - Privilege Escalation
CVSS 7.0
CVE-2010-5158
DefenseWall Personal Firewall 3.00 - Privilege Escalation
CVE-2010-5157
Comodo Internet Security <4.1.149672.916 - Privilege Escalation
CVE-2010-5156
CA Internet Security Suite Plus 2010 6.0.0.272 - Privilege Escalation
CVE-2010-5155
Blink Professional 4.6.1 - Privilege Escalation
CVE-2010-5154
BitDefender Total Security 2010 13.0.20.347 - Privilege Escalation
CVE-2010-5153 MEDIUM
Avira Premium Security Suite <10.0.0.536 - Privilege Escalation
CVSS 5.3
CVE-2010-5152
AVG Internet Security <9.0.791 - Privilege Escalation
CVE-2010-5151
avast! Internet Security <5.0.462 - Privilege Escalation
CVE-2010-5150
3D EQSecure Professional Edition <4.2 - Privilege Escalation
CVE-2010-5074
Firefox < 3.6.24 - Timing Attack via CSS Token Sequence Processing
CVE-2010-4807
IBM Web Content Manager 7.0.0.1 - Authenticated Denial of Service via Recursive Query Race Condition
CVE-2010-4765
OTRS < 2.4.8 - Authenticated Race Condition in FileWrite Method
CVE-2010-4526
Linux Kernel 2.6.11-rc2-2.6.33 - Denial of Service via SCTP ICMP Unreachable Message Race Condition
CVE-2010-4012
iPhone OS 4.0-4.1 - Unauthenticated Passcode Lock Bypass via Emergency Call Screen Race Condition
CVE-2010-2793
Red Hat Enterprise Virtualization <2.2.4 - Privilege Escalation
CVE-2010-4295
VMware Workstation/Player/Server/Fusion Privilege Escalation via Race Condition
Details
Vulnerabilities 2,400
Exploit Likelihood Medium