CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
2,125 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 33 of 43
- CVE-2024-49118HIGHCVSS 8.1EG 8.12024-12-12
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2024-49119HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49120HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49122HIGHCVSS 8.1EG 8.12024-12-12
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2024-49123HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49124HIGHCVSS 8.1EG 8.12024-12-12
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
- CVE-2024-49126HIGHCVSS 8.1EG 8.12024-12-12
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
- CVE-2024-49127HIGHCVSS 8.1EG 8.12024-12-12
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- CVE-2024-49128HIGHCVSS 8.1EG 8.12024-12-12
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2024-49129HIGHCVSS 7.5EG 7.52024-12-12
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
- CVE-2024-49132HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49353HIGHCVSS 7.5EG 7.52024-11-26
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.
- CVE-2024-49724HIGHCVSS 7.0EG 7.02025-01-21
In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privi…
- CVE-2024-49859MEDIUMCVSS 4.7EG 4.72024-10-21
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to check atomic_file in f2fs ioctl interfaces Some f2fs ioctl interfaces like f2fs_ioc_set_pin_file(), f2fs_move_file_range(), and f2fs_defragment_range() miss…
- CVE-2024-49864MEDIUMCVSS 4.7EG 4.72024-10-21
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix a race between socket set up and I/O thread creation In rxrpc_open_socket(), it sets up the socket and then sets up the I/O thread that will handle it. This …
- CVE-2024-49866MEDIUMCVSS 4.7EG 4.72024-10-21
In the Linux kernel, the following vulnerability has been resolved: tracing/timerlat: Fix a race during cpuhp processing There is another found exception that the "timerlat/1" thread was scheduled on CPU0, and lead to timer corruption fi…
- CVE-2024-49872MEDIUMCVSS 4.7EG 4.72024-10-21
In the Linux kernel, the following vulnerability has been resolved: mm/gup: fix memfd_pin_folios alloc race panic If memfd_pin_folios tries to create a hugetlb page, but someone else already did, then folio gets the value -EEXIST here: …
- CVE-2024-49981HIGHCVSS 7.0EG 7.02024-10-21
In the Linux kernel, the following vulnerability has been resolved: media: venus: fix use after free bug in venus_remove due to race condition in venus_probe, core->work is bound with venus_sys_error_handler, which is used to handle erro…
- CVE-2024-50066HIGHCVSS 7.0EG 7.02024-10-23
In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix move_normal_pmd/retract_page_tables race In mremap(), move_page_tables() looks at the type of the PMD entry and the specified address range to figure out …
- CVE-2024-50135MEDIUMCVSS 4.7EG 4.72024-11-05
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix race condition between reset and nvme_dev_disable() nvme_dev_disable() modifies the dev->online_queues field, therefore nvme_pci_update_nr_queues() should …
- CVE-2024-50174MEDIUMCVSS 4.7EG 4.72024-11-08
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix race when converting group handle to group object XArray provides it's own internal lock which protects the internal array when entries are being simult…
- CVE-2024-50183MEDIUMCVSS 4.7EG 4.72024-11-08
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instance Deleting an NPIV instance requires all fabric ndlps to be released before an NPIV's resourc…
- CVE-2024-50297MEDIUMCVSS 4.7EG 4.72024-11-19
In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Enqueue Tx packets in dql before dmaengine starts Enqueue packets in dql after dma engine starts causes race condition. Tx transfer starts once dma…
- CVE-2024-50313MEDIUMCVSS 5.3EG 5.32024-11-12
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.7 only if the basic authentication mech…
- CVE-2024-51505HIGHCVSS 8.0EG 8.02025-02-18
An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race condition to escalate privileges.
- CVE-2024-51515MEDIUMCVSS 6.2EG 6.22024-11-05
Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vulnerability may affect availability.
- CVE-2024-52906MEDIUMCVSS 5.5EG 5.52024-12-25
IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.
- CVE-2024-53088MEDIUMCVSS 4.7EG 4.72024-11-19
In the Linux kernel, the following vulnerability has been resolved: i40e: fix race condition by adding filter's intermediate sync state Fix a race condition in the i40e driver that leads to MAC/VLAN filters becoming corrupted and leaking…
- CVE-2024-53100MEDIUMCVSS 4.7EG 4.72024-11-25
In the Linux kernel, the following vulnerability has been resolved: nvme: tcp: avoid race between queue_lock lock and destroy Commit 76d54bf20cdc ("nvme-tcp: don't access released socket during error recovery") added a mutex_lock() call …
- CVE-2024-53121MEDIUMCVSS 5.5EG 5.52024-12-02
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, lock FTE when checking if active The referenced commits introduced a two-step process for deleting FTEs: - Lock the FTE, delete it from hardware, set the …
- CVE-2024-53122MEDIUMCVSS 5.5EG 5.52024-12-02
In the Linux kernel, the following vulnerability has been resolved: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust Additional active subflows - i.e. created by the in kernel path manager - are included into the subflow lis…
- CVE-2024-53123MEDIUMCVSS 5.5EG 5.52024-12-02
In the Linux kernel, the following vulnerability has been resolved: mptcp: error out earlier on disconnect Eric reported a division by zero splat in the MPTCP protocol: Oops: divide error: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 1 UID: 0 P…
- CVE-2024-53124MEDIUMCVSS 4.7EG 4.72024-12-02
In the Linux kernel, the following vulnerability has been resolved: net: fix data-races around sk->sk_forward_alloc Syzkaller reported this warning: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156…
- CVE-2024-53136MEDIUMCVSS 4.7EG 4.72024-12-04
In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getattr()" Revert d949d1d14fa2 ("mm: shmem: fix data-race in shmem_getattr()") as suggested by Chuck [1]. It is causing de…
- CVE-2024-53160MEDIUMCVSS 4.7EG 4.72024-12-24
In the Linux kernel, the following vulnerability has been resolved: rcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu KCSAN reports a data race when access the krcp->monitor_work.timer.expires variable in the schedule_delayed_mo…
- CVE-2024-53186HIGHCVSS 7.0EG 7.02024-12-27
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in SMB request handling A race condition exists between SMB request handling in `ksmbd_conn_handler_loop()` and the freeing of `ksmbd_conn` in …
- CVE-2024-53476MEDIUMCVSS 5.9EG 5.92024-12-27
A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory restrictions by simultaneously submitting purchase requests from multiple accounts for the same product…
- CVE-2024-54102MEDIUMCVSS 6.1EG 6.12024-12-12
Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-54120MEDIUMCVSS 4.1EG 4.12025-01-08
Race condition vulnerability in the distributed notification module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2024-54122MEDIUMCVSS 6.2EG 6.22024-12-12
Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-54494MEDIUMCVSS 5.9EG 5.92024-12-12
A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An attacker ma…
- CVE-2024-54510MEDIUMCVSS 5.1EG 5.12024-12-12
A race condition was addressed with improved locking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to leak sensit…
- CVE-2024-56441MEDIUMCVSS 4.1EG 4.12025-01-08
Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-56540MEDIUMCVSS 4.7EG 4.72024-12-27
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery invocation during probe and resume Refactor IPC send and receive functions to allow correct handling of operations that should not trigger a…
- CVE-2024-56552MEDIUMCVSS 4.7EG 4.72024-12-27
In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc_submit: fix race around suspend_pending Currently in some testcases we can trigger: xe 0000:03:00.0: [drm] Assertion `exec_queue_destroyed(q)` failed! .... W…
- CVE-2024-56556HIGHCVSS 7.0EG 7.02024-12-27
In the Linux kernel, the following vulnerability has been resolved: binder: fix node UAF in binder_add_freeze_work() In binder_add_freeze_work() we iterate over the proc->nodes with the proc->inner_lock held. However, this lock is tempor…
- CVE-2024-56568MEDIUMCVSS 4.7EG 4.72024-12-27
In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu: Defer probe of clients after smmu device bound Null pointer dereference occurs due to a race between smmu driver probe and client driver probe, when of_d…
- CVE-2024-56576MEDIUMCVSS 4.7EG 4.72024-12-27
In the Linux kernel, the following vulnerability has been resolved: media: i2c: tc358743: Fix crash in the probe error path when using polling If an error occurs in the probe() function, we should remove the polling timer that was alarme…
- CVE-2024-56635HIGHCVSS 7.0EG 7.02024-12-27
In the Linux kernel, the following vulnerability has been resolved: net: avoid potential UAF in default_operstate() syzbot reported an UAF in default_operstate() [1] Issue is a race between device and netns dismantles. After calling __…
- CVE-2024-56637MEDIUMCVSS 4.7EG 4.72024-12-27
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Hold module reference while requesting a module User space may unload ip_set.ko while it is itself requesting a set type backend module, leading to a k…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →