CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Description
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-26 · CAPEC-29
CVEs mapped to this weakness (2,597)
page 10 of 130| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-41774 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41773 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41771 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41770 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41769 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41768 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41767 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41765 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-38166 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-41915 | Hig | 0.53 | 8.1 | 0.01 | Sep 9, 2023 | OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0. | ||
| CVE-2023-32258 | Hig | 0.53 | 8.1 | 0.03 | Jul 24, 2023 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an object. An attacker… | ||
| CVE-2023-32257 | Hig | 0.53 | 8.1 | 0.02 | Jul 24, 2023 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when performing operations on an object. An… | ||
| CVE-2023-33170 | Hig | 0.53 | 8.1 | 0.02 | Jul 11, 2023 | ASP.NET and Visual Studio Security Feature Bypass Vulnerability | ||
| CVE-2023-24903 | Hig | 0.53 | 8.1 | 0.01 | May 9, 2023 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | ||
| CVE-2023-21712 | Hig | 0.53 | 8.1 | 0.01 | Apr 27, 2023 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-23404 | Hig | 0.53 | 8.1 | 0.01 | Mar 14, 2023 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-42951 | Hig | 0.53 | 8.1 | 0.01 | Feb 6, 2023 | An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can… | ||
| CVE-2021-36532 | Hig | 0.53 | 8.1 | 0.01 | Feb 3, 2023 | Race condition vulnerability discovered in portfolioCMS 1.0 allows remote attackers to run arbitrary code via fileExt parameter to localhost/admin/uploads.php. | ||
| CVE-2023-21679 | Hig | 0.53 | 8.1 | 0.01 | Jan 10, 2023 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | ||
| CVE-2023-21546 | Hig | 0.53 | 8.1 | 0.01 | Jan 10, 2023 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability |
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
- risk 0.53cvss 8.1epss 0.03
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an object. An attacker…
- risk 0.53cvss 8.1epss 0.02
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when performing operations on an object. An…
- risk 0.53cvss 8.1epss 0.02
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can…
- risk 0.53cvss 8.1epss 0.01
Race condition vulnerability discovered in portfolioCMS 1.0 allows remote attackers to run arbitrary code via fileExt parameter to localhost/admin/uploads.php.
- risk 0.53cvss 8.1epss 0.01
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability