CWE-667
675 CVEs • Abstraction: Class
Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
CVEs (675)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Google Linuxfoundation3Android Iot YoctoYoctoJan 7, 2025 Jun 6, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID...Show more |
2Google Linuxfoundation3Android Iot YoctoYoctoJan 7, 2025 Jun 6, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID...Show more |
2Google Linuxfoundation3Android Iot YoctoYoctoJan 7, 2025 Jun 6, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID...Show more |
2Google Linuxfoundation3Android Iot YoctoYoctoJan 7, 2025 Jun 6, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...Show more |
2Google Linuxfoundation3Android Iot YoctoYoctoJan 8, 2025 Jun 6, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...Show more |
Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of serv...Show more |
Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5. |
4Debian FedoraprojectLinux+1 more8Debian Linux FedoraH300s Firmware+5 moreNov 21, 2024 Apr 25, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component. |
3Debian LinuxNetapp8Debian Linux H300s FirmwareH410c Firmware+5 moreNov 21, 2024 Apr 24, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabil...Show more |
In MediaCodec.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...Show more |
In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. U...Show more |
In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID:...Show more |
In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID:...Show more |
In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more |
An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC or MS-MIC card and SRX Series allows an unauthenticated, network-based attacker to cause a flow processing daemon (fl...Show more |
Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds. |
5Illumos JoyentOmniosce+2 more5Illumos OmniosOpenindiana+2 moreApr 14, 2025 Dec 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and...Show more |
In l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more |
If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a deni...Show more |
2Debian Linux2Debian Linux Linux KernelApr 23, 2025 Dec 7, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced anothe...Show more |