CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Description
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-26 · CAPEC-29
CVEs mapped to this weakness (2,608)
page 60 of 131| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34528 | Hig | 0.43 | 7.7 | 0.00 | May 6, 2024 | WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation. | ||
| CVE-2023-35351 | Med | 0.43 | 6.6 | 0.01 | Jul 11, 2023 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | ||
| CVE-2023-35346 | Med | 0.43 | 6.6 | 0.01 | Jul 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-35310 | Med | 0.43 | 6.6 | 0.01 | Jul 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-28308 | Med | 0.43 | 6.6 | 0.01 | Apr 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-28307 | Med | 0.43 | 6.6 | 0.01 | Apr 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-28306 | Med | 0.43 | 6.6 | 0.01 | Apr 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-28305 | Med | 0.43 | 6.6 | 0.01 | Apr 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-28278 | Med | 0.43 | 6.6 | 0.01 | Apr 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2022-30214 | Med | 0.43 | 6.6 | 0.01 | Jul 12, 2022 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2022-30205 | Med | 0.43 | 6.6 | 0.01 | Jul 12, 2022 | Windows Group Policy Elevation of Privilege Vulnerability | ||
| CVE-2022-26829 | Med | 0.43 | 6.6 | 0.02 | Apr 15, 2022 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2022-26822 | Med | 0.43 | 6.6 | 0.02 | Apr 15, 2022 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2022-26821 | Med | 0.43 | 6.6 | 0.02 | Apr 15, 2022 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2022-26820 | Med | 0.43 | 6.6 | 0.02 | Apr 15, 2022 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2022-26819 | Med | 0.43 | 6.6 | 0.02 | Apr 15, 2022 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2022-26817 | Med | 0.43 | 6.6 | 0.02 | Apr 15, 2022 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2022-26814 | Med | 0.43 | 6.6 | 0.02 | Apr 15, 2022 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2019-19580 | Med | 0.43 | 6.6 | 0.01 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421. XSA-299 addressed several critical issues in… | ||
| CVE-2016-8745 | Hig | 0.43 | 7.5 | 0.16 | Aug 10, 2017 | A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0.39, 7.0.0 to 7.0.73 and 6.0.16 to 6.0.48 resulted in the current Processor object being added to the Processor cache multiple… |
- risk 0.43cvss 7.7epss 0.00
WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation.
- risk 0.43cvss 6.6epss 0.01
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows Group Policy Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.02
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.02
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.02
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.02
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.02
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.02
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.02
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.01
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421. XSA-299 addressed several critical issues in…
- risk 0.43cvss 7.5epss 0.16
A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0.39, 7.0.0 to 7.0.73 and 6.0.16 to 6.0.48 resulted in the current Processor object being added to the Processor cache multiple…