CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,483 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 3 of 50
- CVE-2010-0923MEDIUMCVSS v2 6.9EG 6.92010-03-03
Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Ente…
- CVE-2010-1123LOWCVSS v2 2.1EG 2.12010-03-26
Chip Salzenberg Deliver does not properly associate a lockfile with the user who created the file, which allows local users to cause a denial of service (blockage of incoming e-mail) by creating lockfiles for arbitrary mailboxes.
- CVE-2010-1151MEDIUMCVSS v2 6.8EG 6.82010-04-20
Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application fo…
- CVE-2010-1161LOWCVSS v2 3.7EG 3.72010-04-16
Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related to the creation of backup files.
- CVE-2010-1228HIGHCVSS v2 10.0EG 10.02010-04-01
Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.
- CVE-2010-1437HIGHCVSS 7.0EG 7.02010-05-07
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified oth…
- CVE-2010-1775LOWCVSS v2 1.9EG 1.92010-06-22
Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a computer and access arbitrary data, via vect…
- CVE-2010-1888MEDIUMCVSS v2 6.8EG 6.82010-08-11
Race condition in the kernel in Microsoft Windows XP SP3 allows local users to gain privileges via vectors involving thread creation, aka "Windows Kernel Data Initialization Vulnerability."
- CVE-2010-2023MEDIUMCVSS v2 4.4EG 4.42010-06-07
transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by…
- CVE-2010-2024MEDIUMCVSS v2 4.4EG 4.42010-06-07
transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attac…
- CVE-2010-2558HIGHCVSS v2 9.3EG 9.32010-08-11
Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption …
- CVE-2010-2653MEDIUMCVSS v2 6.9EG 6.92010-10-05
Race condition in the hvc_close function in drivers/char/hvc_console.c in the Linux kernel before 2.6.34 allows local users to cause a denial of service or possibly have unspecified other impact by closing a Hypervisor Virtual Console devi…
- CVE-2010-2792LOWCVSS v2 3.3EG 3.32010-08-30
Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client…
- CVE-2010-2793MEDIUMCVSS v2 6.8EG 6.82010-12-08
Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors…
- CVE-2010-2961MEDIUMCVSS v2 6.9EG 6.92010-09-14
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain privileges by modifying this file.
- CVE-2010-3412HIGHCVSS v2 9.3EG 9.32010-09-16
Race condition in the console implementation in Google Chrome before 6.0.472.59 has unspecified impact and attack vectors.
- CVE-2010-3493MEDIUMCVSS v2 4.3EG 4.32010-10-19
Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to t…
- CVE-2010-3864HIGHCVSS v2 7.6EG 7.62010-11-17
Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to execute arbitrary code via client data tha…
- CVE-2010-4012MEDIUMCVSS v2 6.2EG 6.22010-12-08
Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call screen, then quickly pressing the Sleep/Wake button.
- CVE-2010-4248MEDIUMCVSS v2 4.9EG 4.92010-11-30
Race condition in the __exit_signal function in kernel/exit.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors related to multithreaded exec, the use of a thread group leader in kernel/posix…
- CVE-2010-4295MEDIUMCVSS v2 6.9EG 6.92010-12-06
Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2…
- CVE-2010-4526HIGHCVSS v2 7.1EG 7.12011-01-11
Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is alrea…
- CVE-2010-4765MEDIUMCVSS v2 4.9EG 4.92011-03-18
Race condition in the Kernel::System::Main::FileWrite method in Open Ticket Request System (OTRS) before 2.4.8 allows remote authenticated users to corrupt the TicketCounter.log data in opportunistic circumstances by creating tickets.
- CVE-2010-4807LOWCVSS v2 3.5EG 3.52011-05-26
Race condition in IBM Web Content Manager (WCM) 7.0.0.1 before CF003 allows remote authenticated users to cause a denial of service (infinite recursive query) via unspecified vectors, related to a StackOverflowError exception.
- CVE-2010-5074MEDIUMCVSS v2 4.3EG 4.32011-12-07
The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it…
- CVE-2010-5150MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in 3D EQSecure Professional Edition 4.2 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware…
- CVE-2010-5151MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in avast! Internet Security 5.0.462 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware det…
- CVE-2010-5152MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in AVG Internet Security 9.0.791 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detect…
- CVE-2010-5153MEDIUMCVSS 5.3EG 5.32012-08-25
Race condition in Avira Premium Security Suite 10.0.0.536 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malw…
- CVE-2010-5154MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in BitDefender Total Security 2010 13.0.20.347 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based …
- CVE-2010-5155MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Blink Professional 4.6.1 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, …
- CVE-2010-5156MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in CA Internet Security Suite Plus 2010 6.0.0.272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-bas…
- CVE-2010-5157MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Comodo Internet Security before 4.1.149672.916 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-bas…
- CVE-2010-5158MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in DefenseWall Personal Firewall 3.00 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware d…
- CVE-2010-5159HIGHCVSS 7.0EG 7.02012-08-25
Race condition in Dr.Web Security Space Pro 6.0.0.03100 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malwar…
- CVE-2010-5160MEDIUMCVSS 4.5EG 4.52012-08-25
Race condition in ESET Smart Security 4.2.35.3 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detecti…
- CVE-2010-5161MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in F-Secure Internet Security 2010 10.00 build 246 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-ba…
- CVE-2010-5162MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in G DATA TotalCare 2010 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via…
- CVE-2010-5163MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Kaspersky Internet Security 2010 9.0.0.736 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based m…
- CVE-2010-5164MEDIUMCVSS 5.3EG 5.32012-08-25
Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-ba…
- CVE-2010-5165MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Malware Defender 2.6.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, vi…
- CVE-2010-5166MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in McAfee Total Protection 2010 10.0.580 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malwar…
- CVE-2010-5167MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detect…
- CVE-2010-5168MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Symantec Norton Internet Security 2010 17.5.0.127 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-…
- CVE-2010-5169HIGHCVSS 7.0EG 7.02012-08-25
Race condition in Online Armor Premium 4.0.0.35 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detect…
- CVE-2010-5170MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Online Solutions Security Suite 1.5.14905.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based …
- CVE-2010-5171MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Outpost Security Suite Pro 6.7.3.3063.452.0726 and 7.0.3330.505.1221 BETA on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but n…
- CVE-2010-5172MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Panda Internet Security 2010 15.01.00 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malwar…
- CVE-2010-5173MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in PC Tools Firewall Plus 6.0.0.88 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware dete…
- CVE-2010-5174MEDIUMCVSS v2 6.2EG 6.22012-08-25
Race condition in Prevx 3.0.5.143 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certa…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →