CWE-362
2,512 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
CVEs (2,512)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG...Show more |
1Adobe 2Flash Player Flash Player Desktop RuntimeMay 6, 2026 Jul 13, 2016 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Race condition in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information via unspecified vectors...Show more |
1Microsoft 4Windows 10 Windows 8.1Windows Rt 8.1+1 moreMay 6, 2026 Jul 13, 2016 N/A· v4 4.7 MEDIUM· v3 1.2 LOW· v2 Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files...Show more |
Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairing that remains present during a session of the primary user, aka intern...Show more |
Buffer overflow in the create_pbuf function in btif/src/btif_hh.c in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows remote attackers to gain privileges via...Show more |
6Novell NtpOpensuse+3 more10Leap Linux Enterprise DesktopLinux Enterprise Server+7 moreMay 6, 2026 Jul 5, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet wit...Show more |
5Ntp OpensuseOracle+2 more12Leap Linux Enterprise DesktopLinux Enterprise Server+9 moreMay 6, 2026 Jul 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 Jul 3, 2016 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel memory by changing a certain length value,...Show more |
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter. |
main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leverag...Show more |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 6, 2026 May 20, 2016 N/A· v4 5.1 MEDIUM· v3 1.9 LOW· v2 Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to obtain sensitive information from kernel memory via unspecifie...Show more |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseMay 6, 2026 May 14, 2016 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requ...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 May 2, 2016 N/A· v4 5.1 MEDIUM· v3 1.9 LOW· v2 Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user...Show more |
2Linux Redhat6Enterprise Linux Compute Node Eus Enterprise Linux For Ibm Z Systems EusEnterprise Linux For Power Big Endian Eus+3 moreMay 6, 2026 May 2, 2016 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by...Show more |
Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (bu...Show more |
sound/core/timer.c in the Linux kernel before 4.4.1 employs a locking approach that does not consider slave timer instances, which allows local users to cause a denial of service (race condition, use-after-free, and syst...Show more |
sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call. |
The snd_timer_interrupt function in sound/core/timer.c in the Linux kernel before 4.4.1 does not properly maintain a certain linked list, which allows local users to cause a denial of service (race condition and system c...Show more |
Race condition in the queue_delete function in sound/core/seq/seq_queue.c in the Linux kernel before 4.4.1 allows local users to cause a denial of service (use-after-free and system crash) by making an ioctl call at a ce...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Apr 27, 2016 N/A· v4 7.4 HIGH· v3 4.4 MEDIUM· v2 Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU. |