CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Description
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-26 · CAPEC-29
CVEs mapped to this weakness (2,597)
page 6 of 130| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-58045 | Hig | 0.56 | 8.6 | 0.00 | Mar 4, 2025 | Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2020-16602 | Hig | 0.56 | 8.1 | 0.06 | Sep 2, 2020 | Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have… | ||
| CVE-2019-10529 | Hig | 0.56 | 8.1 | 0.02 | Nov 6, 2019 | Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2017-7115 | Hig | 0.56 | 8.1 | 0.08 | Oct 23, 2017 | An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption)… | ||
| CVE-2026-41964 | — | Hig | 0.55 | 8.4 | 0.00 | May 15, 2026 | Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability. | |
| CVE-2026-32091 | Hig | 0.55 | 8.4 | 0.00 | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-24930 | Hig | 0.55 | 8.4 | 0.00 | Feb 6, 2026 | UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-68960 | Hig | 0.55 | 8.4 | 0.00 | Jan 14, 2026 | Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-68957 | Hig | 0.55 | 8.4 | 0.00 | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-66328 | Hig | 0.55 | 8.4 | 0.00 | Dec 8, 2025 | Multi-thread race condition vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58303 | Hig | 0.55 | 8.4 | 0.00 | Nov 28, 2025 | UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-27577 | Hig | 0.55 | 8.4 | 0.00 | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. | ||
| CVE-2025-25278 | Hig | 0.55 | 8.4 | 0.00 | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. | ||
| CVE-2024-34732 | Hig | 0.55 | 8.4 | 0.00 | Jan 28, 2025 | In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-32997 | Hig | 0.55 | 8.4 | 0.00 | May 14, 2024 | Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2022-30163 | Hig | 0.55 | 8.5 | 0.02 | Jun 15, 2022 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2022-22057 | Hig | 0.55 | 8.4 | 0.00 | Jun 14, 2022 | Use after free in graphics fence due to a race condition while closing fence file descriptor and destroy graphics timeline simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-1900 | Hig | 0.55 | 8.4 | 0.00 | Jun 9, 2021 | Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2017-16857 | Hig | 0.55 | 8.5 | 0.01 | Dec 5, 2017 | It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin,… | ||
| CVE-2016-8655 | Hig | 0.55 | 7.8 | 0.11 | Dec 8, 2016 | Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and… |
- risk 0.56cvss 8.6epss 0.00
Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.56cvss 8.1epss 0.06
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have…
- risk 0.56cvss 8.1epss 0.02
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.56cvss 8.1epss 0.08
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption)…
- risk 0.55cvss 8.4epss 0.00
Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.55cvss 8.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
- risk 0.55cvss 8.4epss 0.00
UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.55cvss 8.4epss 0.00
Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.55cvss 8.4epss 0.00
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.55cvss 8.4epss 0.00
Multi-thread race condition vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.55cvss 8.4epss 0.00
UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
- risk 0.55cvss 8.4epss 0.00
In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.55cvss 8.4epss 0.00
Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.55cvss 8.5epss 0.02
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.00
Use after free in graphics fence due to a race condition while closing fence file descriptor and destroy graphics timeline simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.55cvss 8.4epss 0.00
Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.55cvss 8.5epss 0.01
It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin,…
- risk 0.55cvss 7.8epss 0.11
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and…