CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,400 vulnerabilities with CWE-362
CVE-2007-3091
Microsoft Windows 2003 Server - Race Condition
CVE-2007-2654
SUSE Linux - Race Condition in xfs_fsr Temporary Directory Creation
CVE-2007-1741
Apache HTTP Server 2.2.3 - Local Privilege Escalation via Race Condition in suexec
CVE-2007-1249
C1 Financial Services Contelligent 9.1.4 - Privilege Escalation
CVE-2007-0099
Microsoft XML Core Services 3.0 - Remote Code Execution via Nested XML Tags in IFRAME
CVE-2006-4245 HIGH
archivemail 0.6.2 - Race Condition via Insecure Temporary File Handling
CVSS 8.1
CVE-2006-6275
Solaris 8-10 - Denial of Service via Race Condition in Kernel
CVE-2006-5178
PHP < 5.1.6 - Race Condition in Symlink Function
CVE-2006-4801
Roxio Toast Titanium 7 - Local Privilege Escalation via Temporary File Race Condition
CVE-2006-0039
Linux kernel <2.6.16 - Buffer Overflow
CVE-2006-2094
Microsoft IE - Race Condition
CVE-2006-1057
gdm - Local Privilege Escalation via .ICEauthority Symlink Race Condition
CVE-2005-2352 HIGH
gs-gpl < 8.56 - Race Condition in Temp File Handling
CVSS 8.1
CVE-2005-4883
Philippe Jounin Tftpd32 < 2.80 - Denial of Service via Invalid Connect Frames
CVE-2005-3240
Microsoft IE - Race Condition
CVE-2004-2491
Opera Browser < 7.53 - URL Spoofing via Race Condition in Address Bar
CVE-2004-2659
Mozilla - Race Condition
CVE-2004-2697
IBM AIX - Privilege Escalation via Symlink Attack on Inventory Scout Daemon Log File
CVE-2004-2698
imwheel < 1.0.0pre11 - Denial of Service via Symlink Attack on PID File
CVE-2003-1438
BEA WebLogic Server 5.1-7.0.0.1 - Unprotected User Data Exposure via Session Replication Race Condition
CVE-2003-1562
OpenSSH <= 3.6.1p2 - Timing Attack via PAM Keyboard-Interactive Authentication
CVE-2002-2244
akfingerd 0.5 - Denial of Service via Symlink to Device File
CVE-2002-2374
Sun PatchPro 2.0 - Race Condition via Unsafe Temporary File Handling
CVE-2000-0864
GNOME esound <= 0.2.19 - Race Condition via Unix Domain Socket Creation
CVE-1999-0861
Microsoft Commercial Internet System - Information Disclosure via SSL ISAPI Filter Race Condition
Details
Vulnerabilities 2,400
Exploit Likelihood Medium