VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,608)

page 71 of 131
  • CVE-2024-20509MedOct 2, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN session or cause a denial of service (DoS) condition for individual users of the…

  • CVE-2024-27267MedAug 14, 2024
    risk 0.38cvss 5.9epss 0.00

    The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads.

  • CVE-2024-27823MedJul 29, 2024
    risk 0.38cvss 5.9epss 0.01

    A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.3, watchOS 10.5. An attacker in a privileged network…

  • CVE-2024-39554MedJul 10, 2024
    risk 0.38cvss 5.9epss 0.00

    A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to inject…

  • CVE-2024-30046MedMay 14, 2024
    risk 0.38cvss 5.9epss 0.02

    Visual Studio Denial of Service Vulnerability

  • CVE-2024-26578MedFeb 22, 2024
    risk 0.38cvss 5.9epss 0.01

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeated submission during registration resulted in the registration of the same user. When users…

  • CVE-2024-21601MedJan 12, 2024
    risk 0.38cvss 5.9epss 0.00

    A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the Flow-processing Daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos). On…

  • CVE-2023-4642MedNov 27, 2023
    risk 0.38cvss 5.9epss 0.00

    The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.

  • CVE-2022-48613MedNov 8, 2023
    risk 0.38cvss 5.9epss 0.00

    Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.

  • CVE-2022-48566MedAug 22, 2023
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.

  • CVE-2023-4049MedAug 1, 2023
    risk 0.38cvss 5.9epss 0.01

    Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

  • CVE-2022-48509MedJul 6, 2023
    risk 0.38cvss 5.9epss 0.00

    Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally.

  • CVE-2023-32570MedMay 10, 2023
    risk 0.38cvss 5.9epss 0.01

    VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.

  • CVE-2021-20251MedMar 6, 2023
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.

  • CVE-2022-22746MedDec 22, 2022
    risk 0.38cvss 5.9epss 0.01

    A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5,…

  • CVE-2022-41116MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.01

    Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

  • CVE-2022-41090MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.01

    Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

  • CVE-2022-44563MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.00

    There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-22208MedOct 18, 2022
    risk 0.38cvss 5.9epss 0.00

    A Use After Free vulnerability in the Routing Protocol Daemon (rdp) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause Denial of Service (DoS). When a BGP session flap happens, a Use After Free of a memory location that…

  • CVE-2022-39006MedSep 16, 2022
    risk 0.38cvss 5.9epss 0.00

    The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.