VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,607)

page 29 of 131
  • CVE-2023-49603HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-56788HigJan 11, 2025
    risk 0.49cvss 7.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: ethernet: oa_tc6: fix tx skb race condition between reference pointers There are two skb pointers to manage tx skb's enqueued from n/w stack. waiting_tx_skb pointer points to the tx skb which needs to be…

  • CVE-2024-11144HigDec 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The crash causes the FTP service to become unavailable, affecting all users and processes that rely on it for file transfers. If the crash occurs during file…

  • CVE-2024-49129HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

  • CVE-2024-53136HigDec 4, 2024
    risk 0.49cvss 7.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getattr()" Revert d949d1d14fa2 ("mm: shmem: fix data-race in shmem_getattr()") as suggested by Chuck [1]. It is causing deadlocks when accessing tmpfs over NFS. …

  • CVE-2024-53122HigDec 2, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust Additional active subflows - i.e. created by the in kernel path manager - are included into the subflow list before starting the 3whs. A racing…

  • CVE-2024-49353HigNov 26, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.

  • CVE-2024-50297HigNov 19, 2024
    risk 0.49cvss 7.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Enqueue Tx packets in dql before dmaengine starts Enqueue packets in dql after dma engine starts causes race condition. Tx transfer starts once dma engine is started and may execute dql…

  • CVE-2024-49864HigOct 21, 2024
    risk 0.49cvss 7.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix a race between socket set up and I/O thread creation In rxrpc_open_socket(), it sets up the socket and then sets up the I/O thread that will handle it. This is a problem, however, as there's a gap…

  • CVE-2023-41833HigSep 16, 2024
    risk 0.49cvss 7.5epss 0.00

    A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-43467HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.01

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

  • CVE-2024-40815HigJul 29, 2024
    risk 0.49cvss 7.5epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer…

  • CVE-2024-6778HigJul 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

  • CVE-2024-20007HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.00

    In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441369; Issue ID: ALPS08441369.

  • CVE-2024-21307HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.02

    Remote Desktop Client Remote Code Execution Vulnerability

  • CVE-2024-20700HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.04

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2023-34438HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-35309HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-29537HigJun 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

  • CVE-2023-1285HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large…