CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,400 vulnerabilities with CWE-362
CVE-2008-2418
Solaris 10 - Denial of Service via STREAMS Administrative Driver Race Condition
CVE-2008-1669
Linux kernel <2.6.25.2 - Code Injection
CVE-2008-1375
Linux kernel <2.6.24.6-2.6.25.1 - DoS
CVE-2008-1684
Solaris 10 - Arbitrary File Write via Symlink Attack on Debug Log
CVE-2008-1570
policyd-weight <0.1.14 beta-16 - Local File Modification
CVE-2008-0055
Apple Mac OS X 10.4.11 - Denial of Service and Privilege Escalation via World-Writable Directory Creation
CVE-2008-0058
Mac OS X 10.4.11 - Remote Code Execution via NSURLConnection Cache Race Condition
CVE-2008-0059
Apple Mac OS X 10.4.11 - Remote Code Execution via NSXML Error Handling Race Condition
CVE-2008-0933
Solaris 10 - Denial of Service via CPU Performance Counters Race Condition
CVE-2008-0379
Crystal Reports XI Release 2 - Buffer Overflow via Enterprise Tree ActiveX Control SelectedSession Method
CVE-2007-4774 MEDIUM
Linux Kernel < 2.4.35 - Race Condition via SIGCONT Signal Flooding
CVSS 5.9
CVE-2007-6429
X.Org Xserver < 1.4.1 - Remote Code Execution via EVI or MIT-SHM Integer Overflow
CVE-2007-6599
OpenAFS 1.3.50-1.4.5 and 1.5.0-1.5.27 - Denial of Service via Callback Linked-List Race Condition
CVE-2007-5847
Apple Mac OS X 10.4.11 - Info Disclosure
CVE-2007-6216
Solaris 10 - Denial of Service via Fibre Channel Protocol Driver Race Condition
CVE-2007-6180
Solaris 8-10 - Denial of Service via RPC Kernel Module Race Condition
CVE-2007-6077
Rails 1.2.4 - Session Fixation via Incomplete Cookie Protection
CVE-2007-4696
Apple Mac OS X <10.4.11 - Info Disclosure
CVE-2007-5794
nss_ldap - Race Condition in LDAP Connection Handling
CVE-2007-5154
Aipo and Aipo ASP < 3.0.1.0 - Session Fixation
CVE-2007-5132
Solaris 8-10 - Denial of Service via Thread Context Handling Race Condition
CVE-2007-0997
Linux kernel <2.6.17.7 - DoS/Info Disclosure
CVE-2007-3970
ESET NOD32 Antivirus < 2.2289 - Remote Code Execution via CAB File Parsing
CVE-2007-3478
GD Graphics Library < 2.0.34 - Denial of Service via Race Condition in gdImageStringFTEx
CVE-2007-2400
Safari < 3.0.2 and iPhone OS < 1.0.1 - Race Condition Bypass via Page Update and HTTP Redirect
Details
Vulnerabilities 2,400
Exploit Likelihood Medium