← Back
CWE-362

2,498 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
6Windows 10
Windows 8.1Windows Server+3 more
Jun 17, 2026
Jan 11, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Kernel Elevation of Privilege Vulnerability
1Samba
1Samba
Jun 17, 2026
Jan 11, 2022
N/A· v4
2.5 LOW· v3
1.2 LOW· v2
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note...Show more
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.Show less
1Huawei
1Harmonyos
Jun 17, 2026
Jan 3, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.
1Tokio
1Tokio
Jun 17, 2026
Dec 27, 2021
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.
1Metrics Util Project
1Metrics Util
Jun 17, 2026
Dec 27, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the metrics-util crate before 0.7.0 for Rust. There is a data race and memory corruption because AtomicBucket<T> unconditionally implements the Send and Sync traits.
1Apple
5Iphone Os
Mac Os XMacos+2 more
Nov 21, 2024
Dec 23, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An...Show more
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.Show less
5Debian
FedoraprojectLinux+2 more
12Debian Linux
Enterprise LinuxFedora+9 more
Jun 17, 2026
Dec 22, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.
1Atomix
1Atomix
Jun 17, 2026
Dec 16, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages.
1Google
1Android
Jun 17, 2026
Dec 15, 2021
N/A· v4
4.1 MEDIUM· v3
1.9 LOW· v2
In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User inter...Show more
In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-160822094References: Upstream kernelShow less
1Google
1Android
Jun 17, 2026
Dec 15, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
In synchronous_process_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interacti...Show more
In synchronous_process_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195731663References: N/AShow less
1Google
1Android
Jun 17, 2026
Dec 15, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee...Show more
In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-192085766Show less
3Debian
GoogleLinux
3Android
Debian LinuxLinux Kernel
Jun 17, 2026
Dec 15, 2021
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo...Show more
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernelShow less
2Debian
Mozilla
4Debian Linux
FirefoxFirefox Esr+1 more
Jun 17, 2026
Dec 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. Thi...Show more
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.Show less
1Fortinet
1Fortiweb
Jun 17, 2026
Dec 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurren...Show more
Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with improper synchronization and one of authentication bypass by capture-replay, may allow a remote unauthenticated attacker to circumvent the authentication process and authenticate as a legitimate cluster peer.Show less
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Dec 8, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Dec 8, 2021
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.
1Huawei
1Harmonyos
Jun 17, 2026
Dec 7, 2021
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.
1Huawei
1Harmonyos
Jun 17, 2026
Dec 7, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash.
1Huawei
1Harmonyos
Jun 17, 2026
Dec 7, 2021
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the detection result is tampered with.
1Tmate
1Tmate Ssh Server
Jun 17, 2026
Dec 7, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Insecure creation of temporary directories in tmate-ssh-server 2.3.0 allows a local attacker to compromise the integrity of session handling.