CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,498 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 26 of 50
- CVE-2022-39188MEDIUMCVSS 4.7EG 4.72022-09-02
An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap_mapping_range versus munmap), a device driver can free a page while it still has stale TLB entries. This only occurs i…
- CVE-2022-39328CRITICALCVSS 9.8EG 9.82022-11-08
Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an admi…
- CVE-2022-40130MEDIUMCVSS 4.3EG 4.32022-11-18
Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress.
- CVE-2022-40307MEDIUMCVSS 4.7EG 4.72022-09-09
An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.
- CVE-2022-40310MEDIUMCVSS 4.3EG 4.32022-09-23
Authenticated (subscriber+) Race Condition vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress allows attackers to increase/decrease votes.
- CVE-2022-4037HIGHCVSS 6.4EG 8.52023-01-12
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeov…
- CVE-2022-41035HIGHCVSS 5.3EG 8.32022-10-11
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2022-41039HIGHCVSS 8.1EG 8.12022-11-09
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-41044HIGHCVSS 8.1EG 8.12022-11-09
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-41045HIGHCVSS 7.8EG 7.82022-11-09
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2022-41086MEDIUMCVSS 6.4EG 6.42022-11-09
Windows Group Policy Elevation of Privilege Vulnerability
- CVE-2022-41088HIGHCVSS 8.1EG 8.12022-11-09
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-41090MEDIUMCVSS 5.9EG 5.92022-11-09
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
- CVE-2022-41093HIGHCVSS 7.8EG 7.82022-11-09
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2022-41100HIGHCVSS 7.8EG 7.82022-11-09
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2022-41114HIGHCVSS 7.0EG 7.02022-11-09
Windows Bind Filter Driver Elevation of Privilege Vulnerability
- CVE-2022-41116MEDIUMCVSS 5.9EG 5.92022-11-09
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
- CVE-2022-41118HIGHCVSS 7.5EG 7.52022-11-09
Windows Scripting Languages Remote Code Execution Vulnerability
- CVE-2022-4129MEDIUMCVSS 5.5EG 5.52022-11-28
A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system…
- CVE-2022-41848MEDIUMCVSS 4.2EG 4.22022-09-30
drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition between mgslpc_ioc…
- CVE-2022-41849MEDIUMCVSS 4.2EG 4.22022-09-30
drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and…
- CVE-2022-41850MEDIUMCVSS 4.7EG 4.72022-09-30
roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress.
- CVE-2022-42770MEDIUMCVSS 4.7EG 4.72022-12-06
In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.
- CVE-2022-42771MEDIUMCVSS 4.7EG 4.72022-12-06
In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.
- CVE-2022-42791HIGHCVSS 7.0EG 7.02022-11-01
A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-42803HIGHCVSS 7.0EG 7.02022-11-01
A race condition was addressed with improved locking. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1. An app may be able to execute arbitrary cod…
- CVE-2022-42806HIGHCVSS 7.0EG 7.02022-11-01
A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-42831MEDIUMCVSS 6.4EG 6.42022-11-01
A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.
- CVE-2022-42832MEDIUMCVSS 6.4EG 6.42022-11-01
A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.
- CVE-2022-42864HIGHCVSS 7.0EG 7.02022-12-15
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may…
- CVE-2022-42930HIGHCVSS 7.1EG 7.12022-12-22
If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106.
- CVE-2022-42951HIGHCVSS 8.1EG 8.12023-02-06
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authenticati…
- CVE-2022-44032MEDIUMCVSS 6.4EG 6.42022-10-30
An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4000_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condit…
- CVE-2022-44033MEDIUMCVSS 6.4EG 6.42022-10-30
An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4040_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condit…
- CVE-2022-44034MEDIUMCVSS 6.4EG 6.42022-10-30
An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condit…
- CVE-2022-44551CRITICALCVSS 9.8EG 9.82022-11-09
The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
- CVE-2022-44563MEDIUMCVSS 5.9EG 5.92022-11-09
There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-44669HIGHCVSS 7.0EG 7.02022-12-13
Windows Error Reporting Elevation of Privilege Vulnerability
- CVE-2022-44676HIGHCVSS 8.1EG 8.12022-12-13
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2022-45869MEDIUMCVSS 5.5EG 5.52022-11-30
A race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of service (host OS crash or host OS memory corruption) when nested virtualisation and the TDP MMU are enabled.
- CVE-2022-45884HIGHCVSS 7.0EG 7.02022-11-25
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.
- CVE-2022-45885HIGHCVSS 7.0EG 7.02022-11-25
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.
- CVE-2022-45886HIGHCVSS 7.0EG 7.02022-11-25
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_net.c has a .disconnect versus dvb_device_open race condition that leads to a use-after-free.
- CVE-2022-45887MEDIUMCVSS 4.7EG 4.72022-11-25
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call.
- CVE-2022-45888MEDIUMCVSS 6.4EG 6.42022-11-25
An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device.
- CVE-2022-46174MEDIUMCVSS 4.2EG 4.22022-12-28
efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helpe…
- CVE-2022-46689HIGHCVSS 7.0EG 7.52022-12-15
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may b…
- CVE-2022-46713MEDIUMCVSS 4.7EG 4.72023-02-27
A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system.
- CVE-2022-47331MEDIUMCVSS 4.7EG 4.72023-02-12
In wlan driver, there is a race condition. This could lead to local denial of service in wlan services.
- CVE-2022-48221HIGHCVSS 7.5EG 7.52023-04-04
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. Multiple MSI's get executed out of a standard-user writable directory. Through a race condition and OpLock manipulation, these files can be overwritten by a standard user. T…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →