CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,485 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 11 of 50
- CVE-2017-2616MEDIUMCVSS 5.5EG 5.52018-07-27
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
- CVE-2017-2619HIGHCVSS 7.5EG 7.52018-03-12
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.
- CVE-2017-2636HIGHCVSS 7.0EG 7.82017-03-07
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
- CVE-2017-2898HIGHCVSS 7.5EG 7.52017-11-07
An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Disney. Specially crafted network packets can cause an unsigned firmware to be installed in the device resulting in arbit…
- CVE-2017-3158HIGHCVSS 8.1EG 8.12018-01-18
A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the packet length, resu…
- CVE-2017-5035HIGHCVSS 8.1EG 8.12017-04-24
Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site.
- CVE-2017-5061MEDIUMCVSS 5.3EG 5.32017-10-27
A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2017-5068HIGHCVSS 7.5EG 7.52017-10-27
Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.
- CVE-2017-5427MEDIUMCVSS 5.5EG 5.52018-06-11
A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loa…
- CVE-2017-5899HIGHCVSS 7.0EG 7.02017-03-27
Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.
- CVE-2017-5986MEDIUMCVSS 5.5EG 5.52017-02-18
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an asso…
- CVE-2017-6001HIGHCVSS 7.0EG 7.02017-02-18
Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context.…
- CVE-2017-6167HIGHCVSS 7.5EG 7.52017-12-21
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being executed with different privilege levels than e…
- CVE-2017-6296HIGHCVSS 7.0EG 7.02018-03-06
NVIDIA TrustZone Software contains a TOCTOU issue in the DRM application which may lead to the denial of service or possible escalation of privileges. This issue is rated as moderate.
- CVE-2017-6346HIGHCVSS 7.0EG 7.02017-03-01
Race condition in net/packet/af_packet.c in the Linux kernel before 4.9.13 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that makes PACKET_FANOUT …
- CVE-2017-6408HIGHCVSS 7.0EG 7.02017-03-02
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. A local-privilege-escalation race condition in pbx_exchange can occur when a local user connects to a socket before permissions are secur…
- CVE-2017-6512MEDIUMCVSS 5.9EG 5.92017-06-01
Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.
- CVE-2017-6615MEDIUMCVSS 6.3EG 6.32017-04-20
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that c…
- CVE-2017-6874HIGHCVSS 7.0EG 7.02017-03-14
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain…
- CVE-2017-6979HIGHCVSS 7.0EG 7.02017-05-22
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "IOSurface" component. A race cond…
- CVE-2017-7004HIGHCVSS 7.0EG 7.02018-04-03
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "Security" component. A race condition allows attackers to bypass intended entitlement restrictions …
- CVE-2017-7115HIGHCVSS 8.1EG 8.12017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause …
- CVE-2017-7151HIGHCVSS 7.0EG 7.02019-04-03
A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.
- CVE-2017-7326HIGHCVSS 7.5EG 7.52018-01-19
Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page
- CVE-2017-7368HIGHCVSS 7.0EG 7.02017-06-13
In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.
- CVE-2017-7372HIGHCVSS 7.0EG 7.02017-06-13
In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.
- CVE-2017-7533HIGHCVSS 7.0EG 7.02017-08-05
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that leverages simultaneous execution of the …
- CVE-2017-7543MEDIUMCVSS 5.3EG 5.32018-07-26
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifi…
- CVE-2017-7572HIGHCVSS 8.1EG 8.12017-04-06
The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condition (time of check, time of use). With …
- CVE-2017-8148MEDIUMCVSS 4.7EG 4.72017-11-22
Audio driver in P9 smartphones with software The versions before EVA-AL10C00B389 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the race condition caus…
- CVE-2017-8242MEDIUMCVSS 5.9EG 5.92017-06-13
In all Android releases from CAF using the Linux kernel, a race condition exists in a QTEE driver potentially leading to an arbitrary memory write.
- CVE-2017-8244HIGHCVSS 7.0EG 7.02017-05-12
In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_buf->curr" and "dbg_buf->filled_size" could be modified by different threads at the same time, but they are not protecte…
- CVE-2017-8257HIGHCVSS 7.8EG 7.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, when accessing the sde_rotator debug interface for register reading with multiple processes, one process can free the debug buffer while another process still …
- CVE-2017-8262HIGHCVSS 7.0EG 7.02017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, in some memory allocation and free functions, a race condition can potentially occur leading to a Use After Free condition.
- CVE-2017-8265HIGHCVSS 7.0EG 7.02017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver which can lead to a double free.
- CVE-2017-8266HIGHCVSS 7.0EG 7.02017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.
- CVE-2017-8267HIGHCVSS 7.0EG 7.02017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in an IOCTL handler potentially leading to an integer overflow and then an out-of-bounds write.
- CVE-2017-8270HIGHCVSS 7.0EG 7.02017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a driver potentially leading to a use-after-free condition.
- CVE-2017-8279HIGHCVSS 7.5EG 7.52017-11-16
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, missing race condition protection while updating msg mask table can lead to buffer over-read. Also access to freed memory can h…
- CVE-2017-8280HIGHCVSS 7.0EG 7.02017-09-21
In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store and retrieve operation, there are some potential race conditions which lead to a memory leak and a buffer overflow durin…
- CVE-2017-8281MEDIUMCVSS 4.7EG 4.72017-09-21
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
- CVE-2017-8342HIGHCVSS 8.1EG 8.12017-04-30
Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
- CVE-2017-9676MEDIUMCVSS 4.7EG 4.72017-09-21
In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a lock.
- CVE-2017-9677HIGHCVSS 7.8EG 7.82017-09-21
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, while it is not protected with locks. If …
- CVE-2017-9682MEDIUMCVSS 4.7EG 4.72017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition.
- CVE-2017-9684HIGHCVSS 7.0EG 7.02017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a USB driver can lead to a Use After Free condition.
- CVE-2017-9685HIGHCVSS 8.1EG 8.12017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a WLAN driver can lead to a Use After Free condition.
- CVE-2017-9691MEDIUMCVSS 4.7EG 4.72018-03-30
There is a race condition in Android for MSM, Firefox OS for MSM, and QRD Android that allows to access to already free'd memory in the debug message output functionality contained within the mobicore driver.
- CVE-2017-9697HIGHCVSS 7.0EG 7.02017-10-10
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while reading command registration table entries in diag_dbgfs_read_t…
- CVE-2017-9703HIGHCVSS 7.0EG 7.02017-12-05
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in a Camera driver can lead to a Use After Free condition.
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →