CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,498 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 30 of 50
- CVE-2023-28320MEDIUMCVSS 5.9EG 5.92023-05-26
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to ti…
- CVE-2023-2898MEDIUMCVSS 4.7EG 4.72023-05-26
There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
- CVE-2023-28984MEDIUMCVSS 5.3EG 5.32023-04-17
A Use After Free vulnerability in the Layer 2 Address Learning Manager (l2alm) of Juniper Networks Junos OS on QFX Series allows an adjacent attacker to cause the Packet Forwarding Engine to crash and restart, leading to a Denial of Servic…
- CVE-2023-29537HIGHCVSS 7.5EG 7.52023-06-02
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
- CVE-2023-30543MEDIUMCVSS 5.2EG 5.22023-04-17
@web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may b…
- CVE-2023-30571LOWCVSS 3.9EG 3.92023-05-29
Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thr…
- CVE-2023-30954LOWCVSS 2.7EG 2.72023-11-15
The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized.
- CVE-2023-3108MEDIUMCVSS 6.2EG 6.22023-07-11
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.
- CVE-2023-31083MEDIUMCVSS 4.7EG 4.72023-04-24
An issue was discovered in drivers/bluetooth/hci_ldisc.c in the Linux kernel 6.2. In hci_uart_tty_ioctl, there is a race condition between HCIUARTSETPROTO and HCIUARTGETPROTO. HCI_UART_PROTO_SET is set before hu->proto is set. A NULL point…
- CVE-2023-31225LOWCVSS 3.3EG 3.32023-05-26
The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download failures and affect product availability.
- CVE-2023-32250CRITICALCVSS 9.0EG 9.02023-07-10
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operati…
- CVE-2023-32254CRITICALCVSS 9.8EG 9.82023-07-10
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing opera…
- CVE-2023-32257HIGHCVSS 8.1EG 8.12023-07-24
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when pe…
- CVE-2023-32258HIGHCVSS 8.1EG 8.12023-07-24
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing…
- CVE-2023-32413HIGHCVSS 7.0EG 7.02023-06-23
A race condition was addressed with improved state handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may…
- CVE-2023-32570MEDIUMCVSS 5.9EG 5.92023-05-10
VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.
- CVE-2023-3301MEDIUMCVSS 5.6EG 5.62023-09-13
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an asse…
- CVE-2023-33110HIGHCVSS 7.8EG 7.82024-01-02
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session inde…
- CVE-2023-33170HIGHCVSS 8.1EG 8.12023-07-11
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
- CVE-2023-33203MEDIUMCVSS 6.4EG 6.42023-05-18
The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.
- CVE-2023-33951MEDIUMCVSS 6.7EG 6.72023-07-24
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a loca…
- CVE-2023-3397HIGHCVSS 7.0EG 7.02023-11-01
A race condition occurred between the functions lmLogClose and txEnd in JFS, in the Linux Kernel, executed in different threads. This flaw allows a local attacker with normal user privileges to crash the system or leak internal kernel info…
- CVE-2023-33974HIGHCVSS 7.5EG 7.52023-05-30
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In versions 2023.01 and prior, an attacker can send multiple crafted frames to the device to trigger a …
- CVE-2023-34349MEDIUMCVSS 4.6EG 4.62023-08-11
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-34438HIGHCVSS 7.5EG 7.52023-08-11
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-35309HIGHCVSS 7.5EG 7.52023-07-11
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-35310MEDIUMCVSS 6.6EG 6.62023-07-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-35346MEDIUMCVSS 6.6EG 6.62023-07-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2023-35351MEDIUMCVSS 6.6EG 6.62023-07-11
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
- CVE-2023-35360HIGHCVSS 7.0EG 7.02023-07-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-35361HIGHCVSS 7.0EG 7.02023-07-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-35362HIGHCVSS 7.8EG 7.82023-07-11
Windows Clip Service Elevation of Privilege Vulnerability
- CVE-2023-35378HIGHCVSS 7.0EG 7.02023-08-08
Windows Projected File System Elevation of Privilege Vulnerability
- CVE-2023-35645MEDIUMCVSS 6.4EG 6.42023-10-11
In tbd of tbd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-35823HIGHCVSS 7.0EG 7.02023-06-18
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.
- CVE-2023-35824HIGHCVSS 7.0EG 7.02023-06-18
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c.
- CVE-2023-35826HIGHCVSS 7.0EG 7.02023-06-18
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.
- CVE-2023-35827HIGHCVSS 7.0EG 7.02023-06-18
An issue was discovered in the Linux kernel through 6.3.8. A use-after-free was found in ravb_remove in drivers/net/ethernet/renesas/ravb_main.c.
- CVE-2023-35828HIGHCVSS 7.0EG 7.02023-06-18
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.
- CVE-2023-35829HIGHCVSS 7.0EG 7.02023-06-18
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c.
- CVE-2023-35863MEDIUMCVSS 5.3EG 5.32023-07-05
In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before th…
- CVE-2023-36405HIGHCVSS 7.0EG 7.02023-11-14
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-36698MEDIUMCVSS 4.4EG 4.42023-10-10
Windows Kernel Security Feature Bypass Vulnerability
- CVE-2023-36776HIGHCVSS 7.0EG 7.02023-10-10
Win32k Elevation of Privilege Vulnerability
- CVE-2023-36884CRITICALCVSS 7.5EG 9.0⚠ KEV2023-07-11
Windows Search Remote Code Execution Vulnerability
- CVE-2023-36902HIGHCVSS 7.0EG 7.02023-10-10
Windows Runtime Remote Code Execution Vulnerability
- CVE-2023-37244MEDIUMCVSS 5.3EG 5.32024-05-02
The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be l…
- CVE-2023-3758HIGHCVSS 7.1EG 7.12024-04-18
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
- CVE-2023-37904LOWCVSS 2.6EG 2.62023-07-28
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is pa…
- CVE-2023-38159HIGHCVSS 7.0EG 7.02023-10-10
Windows Graphics Component Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →