CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
2,125 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 26 of 43
- CVE-2023-21031MEDIUMCVSS 4.7EG 4.72023-03-24
In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pr…
- CVE-2023-21095MEDIUMCVSS 4.7EG 4.72023-06-15
In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User inte…
- CVE-2023-21101HIGHCVSS 7.0EG 7.02023-06-15
In multiple functions of WVDrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2023-21178MEDIUMCVSS 4.1EG 4.12023-06-28
In installKey of KeyUtil.cpp, there is a possible failure of file encryption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.…
- CVE-2023-21262LOWCVSS 3.1EG 3.12023-07-13
In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitat…
- CVE-2023-21290MEDIUMCVSS 5.5EG 5.52023-08-14
In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for …
- CVE-2023-21535HIGHCVSS 8.1EG 8.12023-01-10
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2023-21536MEDIUMCVSS 4.7EG 4.72023-01-10
Event Tracing for Windows Information Disclosure Vulnerability
- CVE-2023-21542HIGHCVSS 7.0EG 7.02023-01-10
Windows Installer Elevation of Privilege Vulnerability
- CVE-2023-21546HIGHCVSS 8.1EG 8.12023-01-10
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- CVE-2023-21679HIGHCVSS 8.1EG 8.12023-01-10
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- CVE-2023-21712HIGHCVSS 8.1EG 8.12023-04-27
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-21725MEDIUMCVSS 6.3EG 6.32023-01-10
Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability
- CVE-2023-21733HIGHCVSS 7.0EG 7.02023-01-10
Windows Bind Filter Driver Elevation of Privilege Vulnerability
- CVE-2023-21766MEDIUMCVSS 4.7EG 4.72023-01-10
Windows Overlay Filter Information Disclosure Vulnerability
- CVE-2023-21771HIGHCVSS 7.0EG 7.02023-01-10
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
- CVE-2023-22276MEDIUMCVSS 6.5EG 6.52023-08-11
Race condition in firmware for some Intel(R) Ethernet Controllers and Adapters E810 Series before version 1.7.2.4 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-22310MEDIUMCVSS 6.5EG 6.52023-11-14
Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-22499HIGHCVSS 7.5EG 7.52023-01-17
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to spoof interactive permission prompt by rewriting the prompt to suggest that program is waiting on user confirmation to …
- CVE-2023-23039MEDIUMCVSS 5.7EG 5.72023-02-22
An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between v…
- CVE-2023-23393HIGHCVSS 7.0EG 7.02023-03-14
Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
- CVE-2023-23404HIGHCVSS 8.1EG 8.12023-03-14
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-23407HIGHCVSS 7.1EG 7.12023-03-14
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
- CVE-2023-24042HIGHCVSS 7.5EG 7.52023-01-21
A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.
- CVE-2023-24861HIGHCVSS 7.0EG 7.02023-03-14
Windows Graphics Component Elevation of Privilege Vulnerability
- CVE-2023-24899HIGHCVSS 7.0EG 7.02023-05-09
Windows Graphics Component Elevation of Privilege Vulnerability
- CVE-2023-24903HIGHCVSS 8.1EG 8.12023-05-09
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2023-26980HIGHCVSS 7.0EG 7.02023-04-14
PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process. NOTE: the vendor disputes this…
- CVE-2023-27359HIGHCVSS 8.1EG 9.82024-05-03
TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to …
- CVE-2023-27952MEDIUMCVSS 4.7EG 4.72023-05-08
A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks.
- CVE-2023-28125MEDIUMCVSS 5.9EG 5.92023-05-09
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
- CVE-2023-28126MEDIUMCVSS 5.9EG 5.92023-05-09
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
- CVE-2023-28142MEDIUMCVSS 6.7EG 6.72023-04-18
A Race Condition exists in the Qualys Cloud Agent for Windows platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to escalate privileges limited on the local machine during uninstallation of the Qualys Cloud Agent…
- CVE-2023-28144HIGHCVSS 7.0EG 7.02023-03-14
KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race conditions involving symlinks and elevate_perf_privileges.sh chown calls.
- CVE-2023-28201CRITICALCVSS 9.8EG 9.82023-05-08
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexpected app terminati…
- CVE-2023-28232HIGHCVSS 7.5EG 7.52023-04-11
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-28273HIGHCVSS 7.0EG 7.02023-04-11
Windows Clip Service Elevation of Privilege Vulnerability
- CVE-2023-28278MEDIUMCVSS 6.6EG 6.62023-04-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-28305MEDIUMCVSS 6.6EG 6.62023-04-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-28306MEDIUMCVSS 6.6EG 6.62023-04-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-28307MEDIUMCVSS 6.6EG 6.62023-04-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-28308MEDIUMCVSS 6.6EG 6.62023-04-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-28320MEDIUMCVSS 5.9EG 5.92023-05-26
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to ti…
- CVE-2023-2898MEDIUMCVSS 4.7EG 4.72023-05-26
There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
- CVE-2023-28984MEDIUMCVSS 5.3EG 5.32023-04-17
A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent attacker to cause the Packet Forwarding Engine to crash and restart, leading to a Denial of Servic…
- CVE-2023-29537HIGHCVSS 7.5EG 7.52023-06-02
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
- CVE-2023-30543MEDIUMCVSS 5.2EG 5.22023-04-17
@web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may b…
- CVE-2023-30571LOWCVSS 3.9EG 3.92023-05-29
Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thr…
- CVE-2023-30954LOWCVSS 2.7EG 2.72023-11-15
The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized.
- CVE-2023-3108MEDIUMCVSS 6.2EG 6.22023-07-11
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →