VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,608)

page 78 of 131
  • CVE-2025-64683MedNov 10, 2025
    risk 0.34cvss 5.3epss 0.00

    In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API

  • CVE-2025-54973MedOct 14, 2025
    risk 0.34cvss 5.3epss 0.00

    A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows an attacker to attempt to win a race…

  • CVE-2025-47545MedMay 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker poll-maker allows Leveraging Race Conditions.This issue affects Poll Maker: from n/a through <= 5.7.7.

  • CVE-2025-1493MedMay 5, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service due to concurrent execution of shared resources.

  • CVE-2023-48366MedFeb 12, 2025
    risk 0.34cvss 5.3epss 0.00

    Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2024-50313MedNov 12, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.7 only if the basic authentication mechanism is used by the application),…

  • CVE-2024-10468MedOct 29, 2024
    risk 0.34cvss 5.3epss 0.00

    Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.

  • CVE-2024-47689MedOct 21, 2024
    risk 0.34cvss 5.3epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to don't set SB_RDONLY in f2fs_handle_critical_error() syzbot reports a f2fs bug as below: ------------[ cut here ]------------ WARNING: CPU: 1 PID: 58 at kernel/rcu/sync.c:177…

  • CVE-2023-37244MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attacker to manipulate…

  • CVE-2024-26307MedMar 21, 2024
    risk 0.34cvss 5.3epss 0.00

    Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue…

  • CVE-2024-24864MedFeb 5, 2024
    risk 0.34cvss 5.3epss 0.00

    A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

  • CVE-2024-23196MedFeb 5, 2024
    risk 0.34cvss 5.3epss 0.00

    A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

  • CVE-2024-22386MedFeb 5, 2024
    risk 0.34cvss 5.3epss 0.00

    A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

  • CVE-2023-5313MedSep 30, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as problematic was found in phpkobo Ajax Poll Script 3.18. Affected by this vulnerability is an unknown functionality of the file ajax-poll.php of the component Poll Handler. The manipulation leads to improper enforcement of a single, unique action.…

  • CVE-2023-35863MedJul 5, 2023
    risk 0.34cvss 5.3epss 0.00

    In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.

  • CVE-2023-28984MedApr 17, 2023
    risk 0.34cvss 5.3epss 0.00

    A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent attacker to cause the Packet Forwarding Engine to crash and restart, leading to a Denial of Service (DoS). The PFE may crash when a lot of…

  • CVE-2021-46873MedJan 29, 2023
    risk 0.34cvss 5.3epss 0.00

    WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key…

  • CVE-2022-36318MedDec 22, 2022
    risk 0.34cvss 5.3epss 0.01

    When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

  • CVE-2021-3702MedAug 23, 2022
    risk 0.34cvss 6.3epss 0.00

    A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner's private_data_dir the next time ansible-runner made use of…

  • CVE-2022-27481MedApr 12, 2022
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle resources…