VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,711)

page 6 of 136
  • CVE-2019-12450CriMay 29, 2019
    risk 0.57cvss 9.8epss 0.03

    file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.

  • CVE-2018-18808HigMar 7, 2019
    risk 0.57cvss 8.8epss 0.02

    The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS…

  • CVE-2025-39964HigKEVOct 13, 2025
    risk 0.56cvss 7.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes…

  • CVE-2024-58045HigMar 4, 2025
    risk 0.56cvss 8.6epss 0.00

    Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2020-16602HigSep 2, 2020
    risk 0.56cvss 8.1epss 0.06

    Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have…

  • CVE-2019-10529HigNov 6, 2019
    risk 0.56cvss 8.1epss 0.02

    Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2017-7115HigOct 23, 2017
    risk 0.56cvss 8.1epss 0.08

    An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption)…

  • CVE-2026-41964HigMay 15, 2026
    risk 0.55cvss 8.4epss 0.00

    Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-32091HigApr 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-24930HigFeb 6, 2026
    risk 0.55cvss 8.4epss 0.00

    UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68960HigJan 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68957HigJan 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66328HigDec 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Multi-thread race condition vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58303HigNov 28, 2025
    risk 0.55cvss 8.4epss 0.00

    UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-27577HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

  • CVE-2025-25278HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

  • CVE-2024-34732HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32997HigMay 14, 2024
    risk 0.55cvss 8.4epss 0.00

    Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-30163HigJun 15, 2022
    risk 0.55cvss 8.5epss 0.02

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2022-22057HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Use after free in graphics fence due to a race condition while closing fence file descriptor and destroy graphics timeline simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables