VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,607)

page 46 of 131
  • CVE-2022-23040HigMar 10, 2022
    risk 0.46cvss 7.0epss 0.00

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access…

  • CVE-2022-23039HigMar 10, 2022
    risk 0.46cvss 7.0epss 0.00

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access…

  • CVE-2022-23038HigMar 10, 2022
    risk 0.46cvss 7.0epss 0.00

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access…

  • CVE-2022-23037HigMar 10, 2022
    risk 0.46cvss 7.0epss 0.00

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access…

  • CVE-2022-23036HigMar 10, 2022
    risk 0.46cvss 7.0epss 0.00

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access…

  • CVE-2022-24525HigMar 9, 2022
    risk 0.46cvss 7.0epss 0.00

    Windows Update Stack Elevation of Privilege Vulnerability

  • CVE-2022-24505HigMar 9, 2022
    risk 0.46cvss 7.0epss 0.00

    Windows ALPC Elevation of Privilege Vulnerability

  • CVE-2022-23283HigMar 9, 2022
    risk 0.46cvss 7.0epss 0.00

    Windows ALPC Elevation of Privilege Vulnerability

  • CVE-2021-3752HigFeb 16, 2022
    risk 0.46cvss 7.1epss 0.02

    A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this…

  • CVE-2022-24114HigFeb 4, 2022
    risk 0.46cvss 7.0epss 0.00

    Local privilege escalation due to race condition on application startup. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (macOS) before build 39287

  • CVE-2021-39679HigJan 14, 2022
    risk 0.46cvss 7.0epss 0.00

    In init of vendor_graphicbuffer_meta.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39629HigJan 14, 2022
    risk 0.46cvss 7.0epss 0.00

    In phTmlNfc_Init and phTmlNfc_CleanUp of phTmlNfc.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-21896HigJan 11, 2022
    risk 0.46cvss 7.0epss 0.01

    Windows DWM Core Library Elevation of Privilege Vulnerability

  • CVE-2021-45704HigDec 27, 2021
    risk 0.46cvss 8.1epss 0.01

    An issue was discovered in the metrics-util crate before 0.7.0 for Rust. There is a data race and memory corruption because AtomicBucket unconditionally implements the Send and Sync traits.

  • CVE-2021-44733HigDec 22, 2021
    risk 0.46cvss 7.0epss 0.01

    A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.

  • CVE-2021-0955HigDec 15, 2021
    risk 0.46cvss 7.0epss 0.00

    In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-12951HigNov 16, 2021
    risk 0.46cvss 7.0epss 0.00

    Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations.

  • CVE-2021-0688HigOct 6, 2021
    risk 0.46cvss 7.0epss 0.00

    In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2021-30652HigSep 8, 2021
    risk 0.46cvss 7.0epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.

  • CVE-2021-30786HigSep 8, 2021
    risk 0.46cvss 7.0epss 0.01

    A race condition was addressed with improved state handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.