VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,607)

page 48 of 131
  • CVE-2020-36435HigAug 8, 2021
    risk 0.46cvss 8.1epss 0.01

    An issue was discovered in the ruspiro-singleton crate before 0.4.1 for Rust. In Singleton, Send and Sync do not have bounds checks.

  • CVE-2021-34462HigJul 16, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

  • CVE-2021-0565HigJun 22, 2021
    risk 0.46cvss 7.0epss 0.00

    In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0533HigJun 21, 2021
    risk 0.46cvss 7.0epss 0.00

    In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0532HigJun 21, 2021
    risk 0.46cvss 7.0epss 0.00

    In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0520HigJun 21, 2021
    risk 0.46cvss 7.0epss 0.00

    In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0509HigJun 21, 2021
    risk 0.46cvss 7.0epss 0.00

    In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0508HigJun 21, 2021
    risk 0.46cvss 7.0epss 0.00

    In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0476HigJun 11, 2021
    risk 0.46cvss 7.0epss 0.00

    In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11…

  • CVE-2020-11262HigJun 9, 2021
    risk 0.46cvss 7.0epss 0.00

    A race between command submission and destroying the context can cause an invalid context being added to the list leads to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2020-11250HigJun 9, 2021
    risk 0.46cvss 7.0epss 0.00

    Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…

  • CVE-2021-0432HigApr 13, 2021
    risk 0.46cvss 7.0epss 0.00

    In ClearPullerCacheIfNecessary and ForceClearPullerCache of StatsPullerManager.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-1806HigApr 2, 2021
    risk 0.46cvss 7.0epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in macOS Big Sur 11.2.1, macOS Catalina 10.15.7 Supplemental Update, macOS Mojave 10.14.6 Security Update 2021-002. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2020-27921HigApr 2, 2021
    risk 0.46cvss 7.0epss 0.01

    A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2020-25533HigJan 15, 2021
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An…

  • CVE-2021-0303HigJan 11, 2021
    risk 0.46cvss 7.0epss 0.00

    In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is…

  • CVE-2020-35871HigDec 31, 2020
    risk 0.46cvss 8.1epss 0.01

    An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API data race.

  • CVE-2020-0474HigDec 15, 2020
    risk 0.46cvss 7.0epss 0.00

    In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-11173HigNov 2, 2020
    risk 0.46cvss 7.0epss 0.00

    u'Two threads running simultaneously from user space can lead to race condition in fastRPC driver' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2019-14711HigOct 23, 2020
    risk 0.46cvss 7.0epss 0.00

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass.