VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,607)

page 30 of 131
  • CVE-2023-28232HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

  • CVE-2022-48221HigApr 4, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. Multiple MSI's get executed out of a standard-user writable directory. Through a race condition and OpLock manipulation, these files can be overwritten by a standard user. They then get executed by the elevated…

  • CVE-2022-32764HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.00

    Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-24042HigJan 21, 2023
    risk 0.49cvss 7.5epss 0.01

    A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.

  • CVE-2022-22737HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

  • CVE-2022-41118HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Windows Scripting Languages Remote Code Execution Vulnerability

  • CVE-2016-20015HigSep 20, 2022
    risk 0.49cvss 7.5epss 0.01

    In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown.

  • CVE-2022-35796HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-26701HigMay 26, 2022
    risk 0.49cvss 7.5epss 0.01

    A race condition was addressed with improved locking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-43411HigNov 7, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the old process port. This can be exploited to…

  • CVE-2021-37991HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-29622HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-005 Catalina. Mounting a maliciously crafted NFS network share may lead to arbitrary code execution with system privileges.

  • CVE-2021-30603HigAug 26, 2021
    risk 0.49cvss 7.5epss 0.04

    Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30984HigAug 24, 2021
    risk 0.49cvss 7.5epss 0.02

    A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-38587HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).

  • CVE-2021-21005HigJun 25, 2021
    risk 0.49cvss 7.5epss 0.01

    In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.

  • CVE-2021-29952HigJun 24, 2021
    risk 0.49cvss 7.5epss 0.01

    When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.

  • CVE-2021-30465HigMay 27, 2021
    risk 0.49cvss 8.5epss 0.07

    runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on…

  • CVE-2021-20181HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.00

    A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to…

  • CVE-2021-0270HigApr 22, 2021
    risk 0.49cvss 7.5epss 0.01

    On PTX Series and QFX10k Series devices with the "inline-jflow" feature enabled, a use after free weakness in the Packet Forwarding Engine (PFE) microkernel architecture of Juniper Networks Junos OS may allow an attacker to cause a Denial of Service (DoS) condition whereby one…