VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,607)

page 45 of 131
  • CVE-2022-20082HigJul 6, 2022
    risk 0.46cvss 7.0epss 0.00

    In GPU, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044730; Issue ID: ALPS07044730.

  • CVE-2022-33915HigJun 17, 2022
    risk 0.46cvss 7.0epss 0.00

    Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation. This Hotpatch package is not a replacement for updating to a log4j version that mitigates…

  • CVE-2022-20155HigJun 15, 2022
    risk 0.46cvss 7.0epss 0.00

    In ipu_core_jqs_msg_transport_kernel_write_sync of ipu-core-jqs-msg-transport.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20141HigJun 15, 2022
    risk 0.46cvss 7.0epss 0.00

    In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20118HigMay 10, 2022
    risk 0.46cvss 7.0epss 0.00

    In ion_ioctl and related functions of ion.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20007HigMay 10, 2022
    risk 0.46cvss 7.0epss 0.00

    In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional…

  • CVE-2022-20006HigMay 10, 2022
    risk 0.46cvss 7.0epss 0.00

    In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's under the lockscreen due to a race condition. This could lead to local escalation of privilege if a Guest user is enabled, with no additional execution…

  • CVE-2022-1048HigApr 29, 2022
    risk 0.46cvss 7.0epss 0.00

    A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially…

  • CVE-2022-29582HigApr 22, 2022
    risk 0.46cvss 7.0epss 0.01

    In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.

  • CVE-2022-26828HigApr 15, 2022
    risk 0.46cvss 7.0epss 0.00

    Windows Bluetooth Driver Elevation of Privilege Vulnerability

  • CVE-2022-26827HigApr 15, 2022
    risk 0.46cvss 7.0epss 0.00

    Windows File Server Resource Management Service Elevation of Privilege Vulnerability

  • CVE-2022-26808HigApr 15, 2022
    risk 0.46cvss 7.0epss 0.00

    Windows File Explorer Elevation of Privilege Vulnerability

  • CVE-2022-26807HigApr 15, 2022
    risk 0.46cvss 7.0epss 0.00

    Windows Work Folder Service Elevation of Privilege Vulnerability

  • CVE-2022-24540HigApr 15, 2022
    risk 0.46cvss 7.0epss 0.00

    Windows ALPC Elevation of Privilege Vulnerability

  • CVE-2022-24482HigApr 15, 2022
    risk 0.46cvss 7.0epss 0.00

    Windows ALPC Elevation of Privilege Vulnerability

  • CVE-2022-26357HigApr 5, 2022
    risk 0.46cvss 7.0epss 0.00

    race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The…

  • CVE-2021-39713HigMar 16, 2022
    risk 0.46cvss 7.0epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel

  • CVE-2021-39686HigMar 16, 2022
    risk 0.46cvss 7.0epss 0.00

    In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-23042HigMar 10, 2022
    risk 0.46cvss 7.0epss 0.00

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access…

  • CVE-2022-23041HigMar 10, 2022
    risk 0.46cvss 7.0epss 0.00

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access…