VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,597)

page 8 of 130
  • CVE-2019-9818HigJul 23, 2019
    risk 0.54cvss 8.3epss 0.01

    A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability only affects…

  • CVE-2017-16001HigNov 6, 2017
    risk 0.54cvss 7.8epss 0.01

    In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.

  • CVE-2017-15649HigOct 19, 2017
    risk 0.54cvss 7.8epss 0.01

    net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a…

  • CVE-2017-0161HigSep 13, 2017
    risk 0.54cvss 8.1epss 0.11

    The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it…

  • CVE-2026-66802HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62820HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62778HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.01

    Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-43631HigAug 6, 2026
    risk 0.53cvss 8.1epss 0.00

    llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the…

  • CVE-2026-33827HigApr 14, 2026
    risk 0.53cvss 8.1epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

  • CVE-2026-28891HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

  • CVE-2026-28817HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2025-69871HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage limits. This allows unauthenticated remote…

  • CVE-2026-22856HigJan 14, 2026
    risk 0.53cvss 8.1epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in…

  • CVE-2023-53186HigSep 15, 2025
    risk 0.53cvss 8.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: skbuff: Fix a race between coalescing and releasing SKBs Commit 1effe8ca4e34 ("skbuff: fix coalescing for page_pool fragment recycling") allowed coalescing to proceed with non page pool page and page pool page…

  • CVE-2025-50177HigAug 12, 2025
    risk 0.53cvss 8.1epss 0.04

    Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

  • CVE-2025-7954HigAug 6, 2025
    risk 0.53cvss 8.1epss 0.00

    A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.

  • CVE-2025-32710HigJun 10, 2025
    risk 0.53cvss 8.1epss 0.01

    Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

  • CVE-2025-3886HigApr 27, 2025
    risk 0.53cvss 8.1epss 0.00

    An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.

  • CVE-2025-1801HigMar 3, 2025
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged…

  • CVE-2025-21376HigFeb 11, 2025
    risk 0.53cvss 8.1epss 0.09

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability