CWE-362
2,498 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
CVEs (2,498)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In versions 2023.01 and prior, an attacker can send multiple crafted frames to the d...Show more |
Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race conditi...Show more |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 May 26, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem. |
3Apple HaxxNetapp8Clustered Data Ontap CurlH300s Firmware+5 moreJun 17, 2026 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows...Show more |
The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download failures and affect product availability. |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 May 18, 2023 N/A· v4 6.4 MEDIUM· v3 N/A· v2 The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device. |
2Fedoraproject Videolan2Dav1d FedoraJun 17, 2026 May 10, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit. |
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication mes...Show more |
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an au...Show more |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 May 9, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
1Microsoft 3Windows 11 21h2 Windows 11 22h2Windows Server 2022Jun 17, 2026 May 9, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 Windows Graphics Component Elevation of Privilege Vulnerability |
1Apple 4Ipados Iphone OsMacos+1 moreJun 17, 2026 May 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexp...Show more |
A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks. |
1Microsoft 15Windows 10 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Apr 27, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |
2Linux Netapp2Hci Baseboard Management Controller Linux KernelJun 17, 2026 Apr 24, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow...Show more |
An issue was discovered in drivers/bluetooth/hci_ldisc.c in the Linux kernel 6.2. In hci_uart_tty_ioctl, there is a race condition between HCIUARTSETPROTO and HCIUARTGETPROTO. HCI_UART_PROTO_SET is set before hu->proto i...Show more |
A Race Condition exists in the Qualys Cloud Agent for Windows platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to escalate privileges limited on the local machine during uninstallation of the...Show more |
1Uniswap 4Web3 React Coinbase Wallet Web3 React Eip1193Web3 React Metamask+1 moreJun 17, 2026 Apr 17, 2023 N/A· v4 5.7 MEDIUM· v3 N/A· v2 @web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `us...Show more |
A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent attacker to cause the Packet Forwarding Engine to crash and restart, leading to...Show more |
PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process. NOTE: the v...Show more |