VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,608)

page 72 of 131
  • CVE-2022-30028MedJun 24, 2022
    risk 0.38cvss 5.9epss 0.01

    Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.

  • CVE-2021-3597MedMay 24, 2022
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to…

  • CVE-2022-24686MedFeb 14, 2022
    risk 0.38cvss 5.9epss 0.01

    HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6

  • CVE-2020-35216MedDec 16, 2021
    risk 0.38cvss 5.9epss 0.01

    An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages.

  • CVE-2021-37085MedDec 7, 2021
    risk 0.38cvss 5.9epss 0.00

    There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.

  • CVE-2021-37082MedDec 7, 2021
    risk 0.38cvss 5.9epss 0.00

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash.

  • CVE-2021-36808MedOct 30, 2021
    risk 0.38cvss 5.9epss 0.00

    A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.

  • CVE-2021-36987MedOct 28, 2021
    risk 0.38cvss 5.9epss 0.00

    There is a issue that nodes in the linked list being freed for multiple times in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause the system to restart.

  • CVE-2021-31364MedOct 19, 2021
    risk 0.38cvss 5.9epss 0.01

    An Improper Check for Unusual or Exceptional Conditions vulnerability combined with a Race Condition in the flow daemon (flowd) of Juniper Networks Junos OS on SRX300 Series, SRX500 Series, SRX1500, and SRX5000 Series with SPC2 allows an unauthenticated network based attacker…

  • CVE-2021-1884MedSep 8, 2021
    risk 0.38cvss 5.9epss 0.02

    A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service.

  • CVE-2021-30982MedAug 24, 2021
    risk 0.38cvss 5.9epss 0.01

    A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A remote attacker may be able to cause unexpected application termination or heap corruption.

  • CVE-2021-38191MedAug 8, 2021
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread.

  • CVE-2020-36469MedAug 8, 2021
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in the appendix crate through 2020-11-15 for Rust. For the generic K and V type parameters, Send and Sync are implemented unconditionally.

  • CVE-2020-36466MedAug 8, 2021
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr implements Send and Sync for all types.

  • CVE-2020-15522MedMay 20, 2021
    risk 0.38cvss 5.9epss 0.02

    Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the…

  • CVE-2021-32921MedMay 13, 2021
    risk 0.38cvss 5.9epss 0.02

    An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.

  • CVE-2021-0258MedApr 22, 2021
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attacker to trigger a kernel panic, leading to a Denial of Service (DoS). Continued receipt and processing of these transit packets…

  • CVE-2020-3353MedJun 3, 2020
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a race condition that may occur when syslog…

  • CVE-2020-1629MedApr 8, 2020
    risk 0.38cvss 5.9epss 0.01

    A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process to crash and restart while processing a BGP NOTIFICATION message. This issue affects Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S6; 16.2 versions…

  • CVE-2020-9329MedFeb 21, 2020
    risk 0.38cvss 5.9epss 0.01

    Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.