← Back
CWE-362

2,511 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Comodo
1Antivirus
Jun 17, 2026
Aug 28, 2019
N/A· v4
4.7 MEDIUM· v3
4.7 MEDIUM· v2
A use-after-free flaw in the sandbox container implemented in cmdguard.sys in Comodo Antivirus 12.0.0.6870 can be triggered due to a race condition when handling IRP_MJ_CLEANUP requests in the minifilter for directory ch...Show more
A use-after-free flaw in the sandbox container implemented in cmdguard.sys in Comodo Antivirus 12.0.0.6870 can be triggered due to a race condition when handling IRP_MJ_CLEANUP requests in the minifilter for directory change notifications. This allows an attacker to cause a denial of service (BSOD) when an executable is run inside the container.Show less
1Google
1Android
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...Show more
In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-131105245.Show less
1Linux
1Linux Kernel
Nov 21, 2024
Aug 19, 2019
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caused by a race condition between the functions arc_emac_tx and arc_emac_tx_clean.
1Dell
1Digital Delivery
Jun 17, 2026
Aug 9, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a Universal Windows Platform application by manipulating the inst...Show more
Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a Universal Windows Platform application by manipulating the install software package feature with a race condition and a path traversal exploit in order to run a malicious executable with elevated privileges.Show less
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Jun 17, 2026
Aug 9, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).
1Elastic
1Elasticsearch
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gai...Show more
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.Show less
1Facebook
1Zstandard
Jun 17, 2026
Jul 25, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
1Qualcomm
22Msm8909w Firmware
Msm8996au FirmwareQcs605 Firmware+19 more
Jun 17, 2026
Jul 25, 2019
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Race condition while accessing DMA buffer in jpeg driver in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MSM8909W, MSM8996AU, QC...Show more
Race condition while accessing DMA buffer in jpeg driver in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS605, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM660, SDX20, SDX24Show less
1Qualcomm
24Msm8909w Firmware
Qcs405 FirmwareQcs605 Firmware+21 more
Jun 17, 2026
Jul 25, 2019
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Possible race condition that will cause a use-after-free when writing to two sysfs entries at nearly the same time in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon...Show more
Possible race condition that will cause a use-after-free when writing to two sysfs entries at nearly the same time in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS405, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855, SDM439, SDM660, SDX20, SDX24Show less
1Mozilla
1Firefox
Jun 17, 2026
Jul 23, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67.
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jul 23, 2019
N/A· v4
8.3 HIGH· v3
5.1 MEDIUM· v2
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a san...Show more
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability only affects Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.Show less
1Qualcomm
39Mdm9150 Firmware
Mdm9206 FirmwareMdm9607 Firmware+36 more
Jun 17, 2026
Jul 22, 2019
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon V...Show more
A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM439, SDM630, SDM660, SDX20, SDX24, Snapdragon_High_Med_2016, SXR1130Show less
1Gitlab
1Gitlab
Nov 21, 2024
Jul 10, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11....Show more
GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.
2Deepin
Fedoraproject
2Deepin Clone
Fedora
Jun 17, 2026
Jul 4, 2019
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare...Show more
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a race condition, the attacker can also enter the mount point, thereby preventing a subsequent unmount of the file system.Show less
1F5
1Ssl Orchestrator
Jun 17, 2026
Jul 3, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with S...Show more
On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled.Show less
1Calamares
1Calamares
Jun 17, 2026
Jul 2, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
modules/luksbootkeyfile/main.py in Calamares versions 3.1 through 3.2.10 has a race condition between the time when the LUKS encryption keyfile is created and when secure permissions are set.
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.