CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Description
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-26 · CAPEC-29
CVEs mapped to this weakness (2,607)
page 43 of 131| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-35378 | Hig | 0.46 | 7.0 | 0.00 | Aug 8, 2023 | Windows Projected File System Elevation of Privilege Vulnerability | ||
| CVE-2023-35361 | Hig | 0.46 | 7.0 | 0.00 | Jul 11, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-35360 | Hig | 0.46 | 7.0 | 0.00 | Jul 11, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-32413 | Hig | 0.46 | 7.0 | 0.01 | Jun 23, 2023 | A race condition was addressed with improved state handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to gain root privileges. | ||
| CVE-2023-35827 | Hig | 0.46 | 7.0 | 0.00 | Jun 18, 2023 | An issue was discovered in the Linux kernel through 6.3.8. A use-after-free was found in ravb_remove in drivers/net/ethernet/renesas/ravb_main.c. | ||
| CVE-2023-21101 | Hig | 0.46 | 7.0 | 0.00 | Jun 15, 2023 | In multiple functions of WVDrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-24899 | Hig | 0.46 | 7.0 | 0.00 | May 9, 2023 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2023-26980 | Hig | 0.46 | 7.0 | 0.00 | Apr 14, 2023 | PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process. NOTE: the vendor disputes this because the attack is not feasible: the… | ||
| CVE-2023-28273 | Hig | 0.46 | 7.0 | 0.00 | Apr 11, 2023 | Windows Clip Service Elevation of Privilege Vulnerability | ||
| CVE-2023-28144 | Hig | 0.46 | 7.0 | 0.00 | Mar 14, 2023 | KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race conditions involving symlinks and elevate_perf_privileges.sh chown calls. | ||
| CVE-2023-24861 | Hig | 0.46 | 7.0 | 0.00 | Mar 14, 2023 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2023-23407 | Hig | 0.46 | 7.1 | 0.00 | Mar 14, 2023 | Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | ||
| CVE-2023-23393 | Hig | 0.46 | 7.0 | 0.00 | Mar 14, 2023 | Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability | ||
| CVE-2020-19824 | Hig | 0.46 | 7.0 | 0.00 | Feb 17, 2023 | An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter. | ||
| CVE-2023-21771 | Hig | 0.46 | 7.0 | 0.00 | Jan 10, 2023 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | ||
| CVE-2023-21733 | Hig | 0.46 | 7.0 | 0.00 | Jan 10, 2023 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-21542 | Hig | 0.46 | 7.0 | 0.00 | Jan 10, 2023 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2022-42930 | Hig | 0.46 | 7.1 | 0.00 | Dec 22, 2022 | If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106. | ||
| CVE-2022-42864 | Hig | 0.46 | 7.0 | 0.01 | Dec 15, 2022 | A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with… | ||
| CVE-2022-44669 | Hig | 0.46 | 7.0 | 0.00 | Dec 13, 2022 | Windows Error Reporting Elevation of Privilege Vulnerability |
- risk 0.46cvss 7.0epss 0.00
Windows Projected File System Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
A race condition was addressed with improved state handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to gain root privileges.
- risk 0.46cvss 7.0epss 0.00
An issue was discovered in the Linux kernel through 6.3.8. A use-after-free was found in ravb_remove in drivers/net/ethernet/renesas/ravb_main.c.
- risk 0.46cvss 7.0epss 0.00
In multiple functions of WVDrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.46cvss 7.0epss 0.00
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process. NOTE: the vendor disputes this because the attack is not feasible: the…
- risk 0.46cvss 7.0epss 0.00
Windows Clip Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race conditions involving symlinks and elevate_perf_privileges.sh chown calls.
- risk 0.46cvss 7.0epss 0.00
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter.
- risk 0.46cvss 7.0epss 0.00
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Bind Filter Driver Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106.
- risk 0.46cvss 7.0epss 0.01
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with…
- risk 0.46cvss 7.0epss 0.00
Windows Error Reporting Elevation of Privilege Vulnerability