CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Description
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-26 · CAPEC-29
CVEs mapped to this weakness (2,597)
page 8 of 130| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9818 | Hig | 0.54 | 8.3 | 0.01 | Jul 23, 2019 | A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability only affects… | ||
| CVE-2017-16001 | Hig | 0.54 | 7.8 | 0.01 | Nov 6, 2017 | In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges. | ||
| CVE-2017-15649 | Hig | 0.54 | 7.8 | 0.01 | Oct 19, 2017 | net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a… | ||
| CVE-2017-0161 | Hig | 0.54 | 8.1 | 0.11 | Sep 13, 2017 | The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it… | ||
| CVE-2026-66802 | Hig | 0.53 | 8.1 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62820 | Hig | 0.53 | 8.1 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62778 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-43631 | Hig | 0.53 | 8.1 | 0.00 | Aug 6, 2026 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the… | ||
| CVE-2026-33827 | Hig | 0.53 | 8.1 | 0.01 | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-28891 | Hig | 0.53 | 8.1 | 0.00 | Mar 25, 2026 | A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox. | ||
| CVE-2026-28817 | Hig | 0.53 | 8.1 | 0.00 | Mar 25, 2026 | A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed process may be able to circumvent sandbox restrictions. | ||
| CVE-2025-69871 | Hig | 0.53 | 8.1 | 0.00 | Feb 11, 2026 | A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage limits. This allows unauthenticated remote… | ||
| CVE-2026-22856 | Hig | 0.53 | 8.1 | 0.00 | Jan 14, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in… | ||
| CVE-2023-53186 | Hig | 0.53 | 8.1 | 0.00 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: skbuff: Fix a race between coalescing and releasing SKBs Commit 1effe8ca4e34 ("skbuff: fix coalescing for page_pool fragment recycling") allowed coalescing to proceed with non page pool page and page pool page… | ||
| CVE-2025-50177 | Hig | 0.53 | 8.1 | 0.04 | Aug 12, 2025 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-7954 | Hig | 0.53 | 8.1 | 0.00 | Aug 6, 2025 | A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations. | ||
| CVE-2025-32710 | Hig | 0.53 | 8.1 | 0.01 | Jun 10, 2025 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-3886 | Hig | 0.53 | 8.1 | 0.00 | Apr 27, 2025 | An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component. | ||
| CVE-2025-1801 | Hig | 0.53 | 8.1 | 0.00 | Mar 3, 2025 | A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged… | ||
| CVE-2025-21376 | Hig | 0.53 | 8.1 | 0.09 | Feb 11, 2025 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
- risk 0.54cvss 8.3epss 0.01
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability only affects…
- risk 0.54cvss 7.8epss 0.01
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
- risk 0.54cvss 7.8epss 0.01
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a…
- risk 0.54cvss 8.1epss 0.11
The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it…
- risk 0.53cvss 8.1epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.00
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the…
- risk 0.53cvss 8.1epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
- risk 0.53cvss 8.1epss 0.00
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed process may be able to circumvent sandbox restrictions.
- risk 0.53cvss 8.1epss 0.00
A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage limits. This allows unauthenticated remote…
- risk 0.53cvss 8.1epss 0.00
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in…
- risk 0.53cvss 8.1epss 0.00
In the Linux kernel, the following vulnerability has been resolved: skbuff: Fix a race between coalescing and releasing SKBs Commit 1effe8ca4e34 ("skbuff: fix coalescing for page_pool fragment recycling") allowed coalescing to proceed with non page pool page and page pool page…
- risk 0.53cvss 8.1epss 0.04
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.
- risk 0.53cvss 8.1epss 0.00
A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged…
- risk 0.53cvss 8.1epss 0.09
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability