VYPR

CWE-667

Improper Locking

ClassDraft

Description

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-25 · CAPEC-26 · CAPEC-27

CVEs mapped to this weakness (725)

page 9 of 37
  • CVE-2023-20746MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07519217.

  • CVE-2023-20745MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07560694.

  • CVE-2023-20743MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07519142.

  • CVE-2023-20737MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645167.

  • CVE-2023-20733MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645149.

  • CVE-2023-20619MedFeb 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519159; Issue ID: ALPS07519159.

  • CVE-2023-20618MedFeb 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519184; Issue ID: ALPS07519184.

  • CVE-2022-26473MedOct 7, 2022
    risk 0.44cvss 6.7epss 0.00

    In vdec fmt, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342197; Issue ID: ALPS07342197.

  • CVE-2022-26452MedOct 7, 2022
    risk 0.44cvss 6.7epss 0.00

    In isp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262305; Issue ID: ALPS07262305.

  • CVE-2022-26451MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In ged, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07202966; Issue ID: ALPS07202966.

  • CVE-2022-20376MedAug 11, 2022
    risk 0.44cvss 6.7epss 0.00

    In trusty_log_seq_start of trusty-log.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2022-21775MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: ALPS06479032.

  • CVE-2022-20153MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    In rcu_cblist_dequeue of rcu_segcblist.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20016MedJan 4, 2022
    risk 0.44cvss 6.7epss 0.00

    In vow driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862986; Issue ID: ALPS05862986.

  • CVE-2021-39656MedDec 15, 2021
    risk 0.44cvss 6.7epss 0.00

    In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39649MedDec 15, 2021
    risk 0.44cvss 6.7epss 0.00

    In regmap_exit of regmap.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0625MedOct 25, 2021
    risk 0.44cvss 6.7epss 0.00

    In ccu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05594996; Issue ID: ALPS05594996.

  • CVE-2020-27066MedDec 15, 2020
    risk 0.44cvss 6.7epss 0.00

    In xfrm6_tunnel_free_spi of net/ipv6/xfrm6_tunnel.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-9946MedOct 16, 2020
    risk 0.44cvss 6.8epss 0.00

    This issue was addressed with improved checks. This issue is fixed in iOS 14.0 and iPadOS 14.0, watchOS 7.0. The screen lock may not engage after the specified time period.

  • CVE-2019-17343MedOct 8, 2019
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.