VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,608)

page 73 of 131
  • CVE-2020-3163MedFeb 19, 2020
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software improperly manages…

  • CVE-2007-4774MedJan 15, 2020
    risk 0.38cvss 5.9epss 0.02

    The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptraced process with SIGCONT signals, which can can wake up a PTRACED process.

  • CVE-2014-0245MedJan 2, 2020
    risk 0.38cvss 5.9epss 0.01

    It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take long to execute, it was possible for an unauthenticated remote…

  • CVE-2019-18827MedDec 16, 2019
    risk 0.38cvss 5.9epss 0.01

    On Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code execution. This means that JTAG access is possible when the system is running code from ROM before handing control over to embedded firmware.

  • CVE-2019-14810MedOct 10, 2019
    risk 0.38cvss 5.9epss 0.01

    A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing the possibility of a Denial of Service (DoS) attack on…

  • CVE-2018-19572MedJul 10, 2019
    risk 0.38cvss 5.9epss 0.01

    GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

  • CVE-2019-6627MedJul 3, 2019
    risk 0.38cvss 5.9epss 0.01

    On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled.

  • CVE-2018-4266MedApr 3, 2019
    risk 0.38cvss 5.9epss 0.02

    A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.

  • CVE-2018-7110MedOct 17, 2018
    risk 0.38cvss 5.9epss 0.01

    A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler.

  • CVE-2018-9069MedOct 2, 2018
    risk 0.38cvss 5.9epss 0.01

    In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.

  • CVE-2018-15473MedAug 17, 2018
    risk 0.38cvss 5.3epss 0.99

    OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

  • CVE-2018-10850MedJun 13, 2018
    risk 0.38cvss 5.9epss 0.02

    389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service.

  • CVE-2018-11324MedMay 22, 2018
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated.

  • CVE-2018-5826MedApr 3, 2018
    risk 0.38cvss 5.9epss 0.00

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, due to a race condition, a Use After Free condition can occur in the WLAN driver.

  • CVE-2017-11353MedJul 17, 2017
    risk 0.38cvss 5.9epss 0.01

    yadm (yet another dotfile manager) 1.10.0 has a race condition (related to the behavior of git commands in setting permissions for new files and directories), which potentially allows access to SSH and PGP keys.

  • CVE-2017-8242MedJun 13, 2017
    risk 0.38cvss 5.9epss 0.00

    In all Android releases from CAF using the Linux kernel, a race condition exists in a QTEE driver potentially leading to an arbitrary memory write.

  • CVE-2015-8878MedMay 22, 2016
    risk 0.38cvss 5.9epss 0.01

    main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that performs many temporary-file…

  • CVE-2026-71968MedAug 10, 2026
    risk 0.37cvss 6.7epss 0.00

    OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag…

  • CVE-2026-54497MedJul 17, 2026
    risk 0.37cvss 6.8epss 0.00

    view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain render-scoped objects across calls to render_in; if the same component, collection, or spacer component…

  • CVE-2024-42488MedAug 15, 2024
    risk 0.37cvss 6.8epss 0.01

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause…