CWE-667
734 CVEs • Abstraction: Class
Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
CVEs (734)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianLinux+3 more24A700s Firmware Active Iq Unified ManagerCloud Backup+21 moreJun 17, 2026 May 9, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails. |
2Linux Redhat2Enterprise Mrg Linux KernelJun 17, 2026 May 8, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impac...Show more |
An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge. |
1Qualcomm 41Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+38 moreJun 17, 2026 Dec 12, 2019 N/A· v4 8.1 HIGH· v3 4.4 MEDIUM· v2 Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapd...Show more |
4Debian FedoraprojectGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop+4 moreJun 17, 2026 Dec 10, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code. |
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains. |
In libstagefright, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not...Show more |
In the Android kernel in the FingerTipS touchscreen driver there is a possible use-after-free due to improper locking. This could lead to a local escalation of privilege with System execution privileges needed. User inte...Show more |
In the Android kernel in the mnh driver there is a use after free due to improper locking. This could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...Show more |
In the Android kernel in the synaptics_dsx_htc touchscreen driver there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User...Show more |
In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no addi...Show more |
2Motorola Openwrt3C1 Mwr03 Firmware Cx2l Mwr04l FirmwareLibuciJun 17, 2026 Aug 23, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Aug 7, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock with f_hid. |
In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This could lead to local information disclosure of protected data with no additional execution privilege...Show more |
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the c...Show more |
In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interacti...Show more |
1Hp 4Z4 G4 Core X Workstation Firmware Z4 G4 Workstation FirmwareZ6 G4 Workstation Firmware+1 moreJun 17, 2026 May 29, 2019 N/A· v4 6.8 MEDIUM· v3 9.0 HIGH· v2 HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whos...Show more |
1Hp 4Z4 G4 Core X Workstation Firmware Z4 G4 Workstation FirmwareZ6 G4 Workstation Firmware+1 moreJun 17, 2026 May 29, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whos...Show more |
A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race con...Show more |
1Cisco 2715454 M Wse K9 Firmware Analog Voice Network Interface Modules FirmwareAsa 5500 Firmware+24 moreJun 17, 2026 May 13, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image...Show more |