VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,713)

page 12 of 136
  • CVE-2022-24504HigOct 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

  • CVE-2022-22035HigOct 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

  • CVE-2022-34702HigAug 9, 2022
    risk 0.53cvss 8.1epss 0.01

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

  • CVE-2022-37035HigAug 2, 2022
    risk 0.53cvss 8.1epss 0.03

    An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP…

  • CVE-2021-4207HigApr 29, 2022
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious…

  • CVE-2021-37134HigJan 3, 2022
    risk 0.53cvss 8.1epss 0.00

    Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.

  • CVE-2021-45710HigDec 27, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.

  • CVE-2017-13905HigDec 23, 2021
    risk 0.53cvss 8.1epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.

  • CVE-2021-37074HigDec 8, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.

  • CVE-2021-0870HigOct 22, 2021
    risk 0.53cvss 8.1epss 0.07

    In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9…

  • CVE-2021-29986HigAug 17, 2021
    risk 0.53cvss 8.1epss 0.01

    A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91,…

  • CVE-2020-36463HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>.

  • CVE-2020-36461HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock.

  • CVE-2020-36460HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation of the Send and Sync traits without regard for the inner type.

  • CVE-2020-36459HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore.

  • CVE-2020-36458HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the lexer crate through 2020-11-10 for Rust. For ReaderResult<T, E>, there is an implementation of Sync with a trait bound of T: Send, E: Send.

  • CVE-2020-36456HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell, the Send trait lacks bounds on the contained type.

  • CVE-2020-36454HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the parc crate through 2020-11-14 for Rust. LockWeak has an unconditional implementation of Send without trait bounds on T.

  • CVE-2020-36453HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the scottqueue crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for Queue.

  • CVE-2020-36451HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Send and Sync for RcuCell.