CWE-362
2,511 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
CVEs (2,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System privileges required. User interaction is not needed for exp...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Access Policy Manager ClientNov 21, 2024 Dec 6, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host...Show more |
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operatin...Show more |
In the ClearKey CAS descrambler, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreJun 17, 2026 Nov 14, 2018 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Canonical Systemd Project2Systemd Ubuntu LinuxJun 9, 2025 Oct 26, 2018 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239. |
2Linux Redhat9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+6 moreNov 21, 2024 Oct 22, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b...Show more |
1Hpe 1Service Governance Framework Jun 17, 2026 Oct 17, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different para...Show more |
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerabilit...Show more |
4Canonical DebianLinux+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Oct 3, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker...Show more |
2Hp Lenovo68310s 14isk Firmware 320 15ikbra Firmware320 15ikbrn Firmware+65 moreJun 17, 2026 Oct 2, 2018 N/A· v4 5.9 MEDIUM· v3 7.0 HIGH· v2 In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the co...Show more |
OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter. |
1Qualcomm 19Msm8996au Firmware Sd425 FirmwareSd427 Firmware+16 moreNov 21, 2024 Sep 20, 2018 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_201...Show more |
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a race condition while accessing num of clients in DIAG services can lead to out of boundary access. |
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, LUT configuration is passed down to driver from userspace via ioctl. Simultaneous update from userspace while ke...Show more |
Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been co...Show more |
1St 72Stm32f030c6 Firmware Stm32f030c8 FirmwareStm32f030cc Firmware+69 moreNov 21, 2024 Sep 12, 2018 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) comman...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Sep 10, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using...Show more |
GEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condition and BSoD on Windows) by not checking that user-mode memory is available right before writing to...Show more |
7Canonical DebianNetapp+4 more22Aff Baseboard Management Controller Cloud BackupClustered Data Ontap+19 moreDec 17, 2025 Aug 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c,...Show more |