VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,608)

page 63 of 131
  • CVE-2023-20736MedJun 6, 2023
    risk 0.42cvss 6.4epss 0.00

    In vcu, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645189.

  • CVE-2023-20687MedApr 6, 2023
    risk 0.42cvss 6.4epss 0.00

    In display drm, there is a possible double free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07570772; Issue ID: ALPS07570772.

  • CVE-2023-20686MedApr 6, 2023
    risk 0.42cvss 6.4epss 0.00

    In display drm, there is a possible double free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07570826; Issue ID: ALPS07570826.

  • CVE-2023-20685MedApr 6, 2023
    risk 0.42cvss 6.4epss 0.00

    In vdec, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608575; Issue ID: ALPS07608575.

  • CVE-2023-20684MedApr 6, 2023
    risk 0.42cvss 6.4epss 0.00

    In vdec, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07671069; Issue ID: ALPS07671069.

  • CVE-2023-22499HigJan 17, 2023
    risk 0.42cvss 7.5epss 0.01

    Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to spoof interactive permission prompt by rewriting the prompt to suggest that program is waiting on user confirmation to unrelated action. A malicious program…

  • CVE-2022-4037MedJan 12, 2023
    risk 0.42cvss 6.4epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using…

  • CVE-2022-20567MedDec 16, 2022
    risk 0.42cvss 6.4epss 0.00

    In pppol2tp_create of l2tp_ppp.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid…

  • CVE-2022-32621MedDec 5, 2022
    risk 0.42cvss 6.4epss 0.00

    In isp, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310829; Issue ID: ALPS07310829.

  • CVE-2022-41086MedNov 9, 2022
    risk 0.42cvss 6.4epss 0.00

    Windows Group Policy Elevation of Privilege Vulnerability

  • CVE-2022-32613MedNov 8, 2022
    risk 0.42cvss 6.4epss 0.00

    In vcu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07206340; Issue ID: ALPS07206340.

  • CVE-2022-32612MedNov 8, 2022
    risk 0.42cvss 6.4epss 0.00

    In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID: ALPS07203500.

  • CVE-2022-42832MedNov 1, 2022
    risk 0.42cvss 6.4epss 0.00

    A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-42831MedNov 1, 2022
    risk 0.42cvss 6.4epss 0.00

    A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-26450MedSep 6, 2022
    risk 0.42cvss 6.4epss 0.00

    In apusys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177801; Issue ID: ALPS07177801.

  • CVE-2022-20256MedAug 12, 2022
    risk 0.42cvss 6.4epss 0.00

    In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222572821

  • CVE-2022-20373MedAug 11, 2022
    risk 0.42cvss 6.4epss 0.00

    In st21nfc_loc_set_polaritymode of fc/st21nfc.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-26428MedAug 1, 2022
    risk 0.42cvss 6.4epss 0.00

    In video codec, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06521260; Issue ID: ALPS06521260.

  • CVE-2022-21789MedAug 1, 2022
    risk 0.42cvss 6.4epss 0.00

    In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478101; Issue ID: ALPS06478101.

  • CVE-2022-2160MedJul 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.