CWE-667
719 CVEs • Abstraction: Class
Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
CVEs (719)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain incorrect circumstances, which allows local users to cause a denial of service (panic) by reading zero bytes from the /proc/net/udp...Show more |
The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, whic...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelApr 23, 2026 Sep 29, 2008 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allo...Show more |
The kernel in Red Hat Enterprise Linux 3, when running on SMP systems, allows local users to cause a denial of service (deadlock) by running the shmat function on an shm at the same time that shmctl is removing that shm...Show more |
3Canonical LinuxRedhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 23, 2026 Oct 5, 2006 N/A· v4 7.5 HIGH· v3 3.3 LOW· v2 The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Jun 13, 2006 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseF...Show more |
2Canonical Lksctp2Stream Control Transmission Protocol Ubuntu LinuxApr 16, 2026 May 9, 2006 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which lead...Show more |
2Debian Linux2Debian Linux Linux KernelApr 16, 2026 Nov 27, 2005 N/A· v4 5.5 MEDIUM· v3 4.0 MEDIUM· v2 The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded p...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 16, 2026 Sep 30, 2005 N/A· v4 4.7 MEDIUM· v3 1.2 LOW· v2 Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting...Show more |
2Debian Linux2Debian Linux Linux KernelApr 16, 2026 Aug 4, 2005 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that...Show more |
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connectio...Show more |
3Freebsd NetbsdOpenbsd3Freebsd NetbsdOpenbsdApr 16, 2026 Dec 31, 2002 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file. |
dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file. |
Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an applic...Show more |
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which resu...Show more |
Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access. |
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes. |
2Checkpoint Zonelabs2Zonealarm Zonealarm ProApr 16, 2026 Aug 29, 2001 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting. |
1Concurrent Versions Software Project 1Concurrent Versions Software Apr 16, 2026 Apr 23, 2000 N/A· v4 5.5 MEDIUM· v3 5.0 MEDIUM· v2 Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS...Show more |