VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,597)

page 6 of 130
  • CVE-2024-58045HigMar 4, 2025
    risk 0.56cvss 8.6epss 0.00

    Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2020-16602HigSep 2, 2020
    risk 0.56cvss 8.1epss 0.06

    Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have…

  • CVE-2019-10529HigNov 6, 2019
    risk 0.56cvss 8.1epss 0.02

    Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2017-7115HigOct 23, 2017
    risk 0.56cvss 8.1epss 0.08

    An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption)…

  • CVE-2026-41964HigMay 15, 2026
    risk 0.55cvss 8.4epss 0.00

    Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-32091HigApr 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-24930HigFeb 6, 2026
    risk 0.55cvss 8.4epss 0.00

    UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68960HigJan 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68957HigJan 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66328HigDec 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Multi-thread race condition vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58303HigNov 28, 2025
    risk 0.55cvss 8.4epss 0.00

    UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-27577HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

  • CVE-2025-25278HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

  • CVE-2024-34732HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32997HigMay 14, 2024
    risk 0.55cvss 8.4epss 0.00

    Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-30163HigJun 15, 2022
    risk 0.55cvss 8.5epss 0.02

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2022-22057HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Use after free in graphics fence due to a race condition while closing fence file descriptor and destroy graphics timeline simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-1900HigJun 9, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2017-16857HigDec 5, 2017
    risk 0.55cvss 8.5epss 0.01

    It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin,…

  • CVE-2016-8655HigDec 8, 2016
    risk 0.55cvss 7.8epss 0.11

    Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and…