VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,597)

page 7 of 130
  • CVE-2016-0848HigApr 18, 2016
    risk 0.55cvss 8.4epss 0.00

    Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink target, as demonstrated by…

  • CVE-2026-15119HigJul 8, 2026
    risk 0.54cvss 8.3epss 0.00

    Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-12468HigJun 17, 2026
    risk 0.54cvss 8.3epss 0.00

    Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-12454HigJun 17, 2026
    risk 0.54cvss 8.3epss 0.00

    Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-12022HigJun 11, 2026
    risk 0.54cvss 8.3epss 0.00

    Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

  • CVE-2026-11677HigJun 9, 2026
    risk 0.54cvss 8.3epss 0.00

    Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-10940HigJun 4, 2026
    risk 0.54cvss 8.3epss 0.00

    Race in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-8520HigMay 14, 2026
    risk 0.54cvss 8.3epss 0.00

    Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-6921HigApr 23, 2026
    risk 0.54cvss 8.3epss 0.00

    Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)

  • CVE-2024-49122HigDec 12, 2024
    risk 0.54cvss 8.1epss 0.20

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2022-33636HigAug 9, 2022
    risk 0.54cvss 8.3epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2022-30128HigJun 1, 2022
    risk 0.54cvss 8.3epss 0.02

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-30127HigJun 1, 2022
    risk 0.54cvss 8.3epss 0.02

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2021-0920MedKEVDec 15, 2021
    risk 0.54cvss 6.4epss 0.01

    In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-25395MedKEVJun 11, 2021
    risk 0.54cvss 6.4epss 0.00

    A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

  • CVE-2021-25394MedKEVJun 11, 2021
    risk 0.54cvss 6.4epss 0.00

    A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

  • CVE-2020-1667HigOct 16, 2020
    risk 0.54cvss 8.3epss 0.01

    When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process might be bypassed due to a race condition. Due to this…

  • CVE-2020-1660HigOct 16, 2020
    risk 0.54cvss 8.3epss 0.01

    When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing "URL Filtering service", may…

  • CVE-2020-6575HigSep 21, 2020
    risk 0.54cvss 8.3epss 0.01

    Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-1645HigJul 17, 2020
    risk 0.54cvss 8.3epss 0.01

    When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing "URL Filtering service", may…