← Back
CWE-362

2,511 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
2Manageone
Smc2.0
Jun 17, 2026
Jun 29, 2021
N/A· v4
4.1 MEDIUM· v3
4.7 MEDIUM· v2
There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by perf...Show more
There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by performing some operations. Successful exploitation of this vulnerability may cause the system to crash. Affected product versions include: ManageOne 6.5.1.SPC200, 8.0.0,8.0.0-LCND81, 8.0.0.SPC100, 8.0.1,8.0.RC2, 8.0.RC3, 8.0.RC3.SPC100;SMC2.0 V600R019C10SPC700,V600R019C10SPC702, V600R019C10SPC703,V600R019C10SPC800, V600R019C10SPC900, V600R019C10SPC910, V600R019C10SPC920, V600R019C10SPC921, V600R019C10SPC922, V600R019C10SPC930, V600R019C10SPC931Show less
1Phoenixcontact
15Fl Nat Smn 8tx M Firmware
Fl Nat Smn 8tx FirmwareFl Switch Smcs 14tx/2fx Sm Firmware+12 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device nee...Show more
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.Show less
1Bluetooth
1Bluetooth Core Specification
Jun 17, 2026
Jun 25, 2021
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a crafted packet during the receive window of the listening device before the trans...Show more
Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a crafted packet during the receive window of the listening device before the transmitting device initiates its packet transmission to achieve full MITM status without terminating the link. When applied against devices establishing or using encrypted links, crafted packets may be used to terminate an existing link, but will not compromise the confidentiality or integrity of the link.Show less
1Mozilla
1Firefox
Jun 17, 2026
Jun 24, 2021
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefo...Show more
When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.Show less
1Mozilla
1Thunderbird
Jun 17, 2026
Jun 24, 2021
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.
1Mozilla
1Firefox
Jun 17, 2026
Jun 24, 2021
N/A· v4
3.1 LOW· v3
2.6 LOW· v2
A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as &lt;input t...Show more
A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as &lt;input type="file"&gt;) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not intend to. This vulnerability affects Firefox < 88.Show less
1Huawei
1Ecns280 Td Firmware
Jun 17, 2026
Jun 22, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
There is a race condition vulnerability in eCNS280_TD V100R005C00 and V100R005C10. There is a timing window exists in which the database can be operated by another thread that is operating concurrently. Successful exploi...Show more
There is a race condition vulnerability in eCNS280_TD V100R005C00 and V100R005C10. There is a timing window exists in which the database can be operated by another thread that is operating concurrently. Successful exploit may cause the affected device abnormal.Show less
1Google
1Android
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...Show more
In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174801970Show less
1Google
1Android
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
In decrypt of CryptoPlugin.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exp...Show more
In decrypt of CryptoPlugin.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176495665Show less
1Autoptimize
1Autoptimize
Jun 17, 2026
Jun 21, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a...Show more
The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.Show less
1Google
1Android
Jun 17, 2026
Jun 21, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more
In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185193932Show less
1Google
1Android
Jun 17, 2026
Jun 21, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more
In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185196177Show less
1Google
1Android
Jun 17, 2026
Jun 21, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed....Show more
In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-176237595Show less
1Google
1Android
Jun 17, 2026
Jun 21, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...Show more
In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-176444161Show less
1Google
1Android
Jun 17, 2026
Jun 21, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...Show more
In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-176444154Show less
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...Show more
In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-169252501Show less
1Samsung
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
1Samsung
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
2Intel
Siemens
13Local Manageability Service
Simatic Field Pg M5 FirmwareSimatic Field Pg M6 Firmware+10 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.
3Intel
NetappSiemens
18Aff Bios
BiosCloud Backup+15 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.