CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Description
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-26 · CAPEC-29
CVEs mapped to this weakness (2,608)
page 72 of 131| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30028 | Med | 0.38 | 5.9 | 0.01 | Jun 24, 2022 | Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token. | ||
| CVE-2021-3597 | Med | 0.38 | 5.9 | 0.01 | May 24, 2022 | A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to… | ||
| CVE-2022-24686 | Med | 0.38 | 5.9 | 0.01 | Feb 14, 2022 | HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6 | ||
| CVE-2020-35216 | Med | 0.38 | 5.9 | 0.01 | Dec 16, 2021 | An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages. | ||
| CVE-2021-37085 | Med | 0.38 | 5.9 | 0.00 | Dec 7, 2021 | There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service. | ||
| CVE-2021-37082 | Med | 0.38 | 5.9 | 0.00 | Dec 7, 2021 | There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash. | ||
| CVE-2021-36808 | Med | 0.38 | 5.9 | 0.00 | Oct 30, 2021 | A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115. | ||
| CVE-2021-36987 | Med | 0.38 | 5.9 | 0.00 | Oct 28, 2021 | There is a issue that nodes in the linked list being freed for multiple times in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause the system to restart. | ||
| CVE-2021-31364 | Med | 0.38 | 5.9 | 0.01 | Oct 19, 2021 | An Improper Check for Unusual or Exceptional Conditions vulnerability combined with a Race Condition in the flow daemon (flowd) of Juniper Networks Junos OS on SRX300 Series, SRX500 Series, SRX1500, and SRX5000 Series with SPC2 allows an unauthenticated network based attacker… | ||
| CVE-2021-1884 | Med | 0.38 | 5.9 | 0.02 | Sep 8, 2021 | A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service. | ||
| CVE-2021-30982 | Med | 0.38 | 5.9 | 0.01 | Aug 24, 2021 | A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A remote attacker may be able to cause unexpected application termination or heap corruption. | ||
| CVE-2021-38191 | Med | 0.38 | 5.9 | 0.01 | Aug 8, 2021 | An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread. | ||
| CVE-2020-36469 | Med | 0.38 | 5.9 | 0.01 | Aug 8, 2021 | An issue was discovered in the appendix crate through 2020-11-15 for Rust. For the generic K and V type parameters, Send and Sync are implemented unconditionally. | ||
| CVE-2020-36466 | Med | 0.38 | 5.9 | 0.01 | Aug 8, 2021 | An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr implements Send and Sync for all types. | ||
| CVE-2020-15522 | Med | 0.38 | 5.9 | 0.02 | May 20, 2021 | Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the… | ||
| CVE-2021-32921 | Med | 0.38 | 5.9 | 0.02 | May 13, 2021 | An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker. | ||
| CVE-2021-0258 | Med | 0.38 | 5.9 | 0.01 | Apr 22, 2021 | A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attacker to trigger a kernel panic, leading to a Denial of Service (DoS). Continued receipt and processing of these transit packets… | ||
| CVE-2020-3353 | Med | 0.38 | 5.9 | 0.01 | Jun 3, 2020 | A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a race condition that may occur when syslog… | ||
| CVE-2020-1629 | Med | 0.38 | 5.9 | 0.01 | Apr 8, 2020 | A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process to crash and restart while processing a BGP NOTIFICATION message. This issue affects Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S6; 16.2 versions… | ||
| CVE-2020-9329 | Med | 0.38 | 5.9 | 0.01 | Feb 21, 2020 | Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition. |
- risk 0.38cvss 5.9epss 0.01
Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.
- risk 0.38cvss 5.9epss 0.01
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to…
- risk 0.38cvss 5.9epss 0.01
HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6
- risk 0.38cvss 5.9epss 0.01
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages.
- risk 0.38cvss 5.9epss 0.00
There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.
- risk 0.38cvss 5.9epss 0.00
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash.
- risk 0.38cvss 5.9epss 0.00
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
- risk 0.38cvss 5.9epss 0.00
There is a issue that nodes in the linked list being freed for multiple times in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause the system to restart.
- risk 0.38cvss 5.9epss 0.01
An Improper Check for Unusual or Exceptional Conditions vulnerability combined with a Race Condition in the flow daemon (flowd) of Juniper Networks Junos OS on SRX300 Series, SRX500 Series, SRX1500, and SRX5000 Series with SPC2 allows an unauthenticated network based attacker…
- risk 0.38cvss 5.9epss 0.02
A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service.
- risk 0.38cvss 5.9epss 0.01
A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A remote attacker may be able to cause unexpected application termination or heap corruption.
- risk 0.38cvss 5.9epss 0.01
An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread.
- risk 0.38cvss 5.9epss 0.01
An issue was discovered in the appendix crate through 2020-11-15 for Rust. For the generic K and V type parameters, Send and Sync are implemented unconditionally.
- risk 0.38cvss 5.9epss 0.01
An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr implements Send and Sync for all types.
- risk 0.38cvss 5.9epss 0.02
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the…
- risk 0.38cvss 5.9epss 0.02
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
- risk 0.38cvss 5.9epss 0.01
A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attacker to trigger a kernel panic, leading to a Denial of Service (DoS). Continued receipt and processing of these transit packets…
- risk 0.38cvss 5.9epss 0.01
A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a race condition that may occur when syslog…
- risk 0.38cvss 5.9epss 0.01
A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process to crash and restart while processing a BGP NOTIFICATION message. This issue affects Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S6; 16.2 versions…
- risk 0.38cvss 5.9epss 0.01
Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.