← Back
CWE-362

2,604 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,604)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Canonical
DebianFedoraproject+3 more
8Debian Linux
FedoraLinux Enterprise Desktop+5 more
Apr 23, 2026
May 2, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via...Show more
Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.Show less
1Sun
1Solaris
Apr 23, 2026
Apr 6, 2008
N/A· v4
N/A· v3
4.7 MEDIUM· v2
inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.
1Policyd Weight
1Policyd Weight
Apr 23, 2026
Mar 31, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check o...Show more
Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Mar 18, 2008
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Mar 18, 2008
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent...Show more
Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Mar 18, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a...Show more
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.Show less
1Sun
1Solaris
Apr 23, 2026
Feb 25, 2008
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_rest...Show more
Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_restore.Show less
1Businessobjects
1Crystal Reports Xi
Apr 23, 2026
Jan 22, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code v...Show more
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow.Show less
1X.org
3Evi
Mit ShmXserver
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amoun...Show more
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.Show less
2Debian
Openafs
2Debian Linux
Openafs
Apr 23, 2026
Jan 4, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which...Show more
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.Show less
1Apple
1Mac Os X
Apr 23, 2026
Dec 19, 2007
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Race condition in the CFURLWriteDataAndPropertiesToResource API in Core Foundation in Apple Mac OS X 10.4.11 creates files with insecure permissions, which might allow local users to obtain sensitive information.
1Sun
2Solaris
Sunos
Apr 23, 2026
Dec 4, 2007
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some programs that access hardware resources, a...Show more
Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some programs that access hardware resources, as demonstrated by the (1) cfgadm and (2) format programs.Show less
1Sun
1Solaris
Apr 23, 2026
Nov 30, 2007
N/A· v4
N/A· v3
7.6 HIGH· v2
Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL dereference and panic) via unspecified vectors.
1Rubyonrails
1Rails
Apr 23, 2026
Nov 21, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to...Show more
The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to "page transitions" in Safari.
1Nss Ldap
1Nss Ldap
Apr 23, 2026
Nov 13, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP conn...Show more
Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.Show less
1Aimluck
2Aipo
Aipo Asp
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Session fixation vulnerability in Aipo and Aipo ASP 3.0.1.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
1Sun
1Solaris
Apr 23, 2026
Sep 27, 2007
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors related to "the handling of thread contexts."
1Linux
1Linux Kernel
Apr 23, 2026
Sep 18, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (system crash), obtain sensitive information (kernel memory contents), or g...Show more
Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (system crash), obtain sensitive information (kernel memory contents), or gain privileges via unspecified vectors related to a potentially dropped ipipe lock during a race between two pipe readers.Show less
1Eset
1Nod32 Antivirus
Apr 23, 2026
Jul 25, 2007
N/A· v4
N/A· v3
7.6 HIGH· v2
Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap corruption.