VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,712)

page 13 of 136
  • CVE-2020-36445HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the convec crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for ConVec.

  • CVE-2020-36444HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the async-coap crate through 2020-12-08 for Rust. Send and Sync are implemented for ArcGuard<RC, T> without trait bounds on RC.

  • CVE-2020-36442HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the beef crate before 0.5.0 for Rust. beef::Cow has no Sync bound on its Send trait.

  • CVE-2021-22428HigAug 2, 2021
    risk 0.53cvss 8.1epss 0.01

    There is an Incomplete Cleanup Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.

  • CVE-2021-22427HigAug 2, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a Heap-based Buffer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.

  • CVE-2021-22384HigAug 2, 2021
    risk 0.53cvss 8.1epss 0.01

    There is an Information Disclosure Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.

  • CVE-2021-0514HigJul 14, 2021
    risk 0.53cvss 8.1epss 0.01

    In several functions of the V8 library, there is a possible use after free due to a race condition. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-24377HigJun 21, 2021
    risk 0.53cvss 8.1epss 0.01

    The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the…

  • CVE-2020-14104HigApr 8, 2021
    risk 0.53cvss 8.1epss 0.01

    A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.

  • CVE-2018-20316HigJan 7, 2021
    risk 0.53cvss 8.1epss 0.01

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.

  • CVE-2018-20315HigJan 7, 2021
    risk 0.53cvss 8.1epss 0.01

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

  • CVE-2018-20314HigJan 7, 2021
    risk 0.53cvss 8.1epss 0.01

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

  • CVE-2018-20313HigJan 7, 2021
    risk 0.53cvss 8.1epss 0.01

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

  • CVE-2018-20312HigJan 7, 2021
    risk 0.53cvss 8.1epss 0.01

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.

  • CVE-2018-20311HigJan 7, 2021
    risk 0.53cvss 8.1epss 0.01

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

  • CVE-2018-20310HigJan 7, 2021
    risk 0.53cvss 8.1epss 0.01

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

  • CVE-2018-20309HigJan 7, 2021
    risk 0.53cvss 8.1epss 0.01

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

  • CVE-2020-35882HigDec 31, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the rocket crate before 0.4.5 for Rust. LocalRequest::clone creates more than one mutable references to the same object, possibly causing a data race.

  • CVE-2020-35874HigDec 31, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the internment crate through 2020-05-28 for Rust. ArcIntern::drop has a race condition and resultant use-after-free.

  • CVE-2020-24696HigOct 2, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can trigger a race condition leading to a crash, or possibly arbitrary code execution, by sending crafted queries with a GSS-TSIG…