CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,485 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 7 of 50
- CVE-2014-3701HIGHCVSS 8.1EG 8.12019-12-15
eDeploy has tmp file race condition flaws
- CVE-2014-3856HIGHCVSS 7.0EG 7.02020-01-28
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
- CVE-2014-3940MEDIUMCVSS v2 4.0EG 4.02014-06-05
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by…
- CVE-2014-4353MEDIUMCVSS v2 4.3EG 4.32014-09-18
Race condition in iMessage in Apple iOS before 8 allows attackers to obtain sensitive information by leveraging the presence of an attachment after the deletion of its parent (1) iMessage or (2) MMS.
- CVE-2014-4386LOWCVSS v2 1.9EG 1.92014-09-18
Race condition in the App Installation feature in Apple iOS before 8 allows local users to gain privileges and install unverified apps by leveraging /tmp write access.
- CVE-2014-4438MEDIUMCVSS v2 6.9EG 6.92014-10-18
Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by leveraging an unattended workstation on which screen locking had been attempted.
- CVE-2014-4652LOWCVSS v2 1.9EG 1.92014-07-03
Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kern…
- CVE-2014-4699MEDIUMCVSS v2 6.9EG 6.92014-07-09
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition…
- CVE-2014-4813MEDIUMCVSS v2 6.9EG 6.92015-02-13
Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0.0 through 6.1.5.6, 6.2 before 6.2.5.4, 6.3 before 6.3.2.3, 6.4 before 6.4.2.1, and 7.1 before 7.1.1 on UNIX and Linux …
- CVE-2014-4995HIGHCVSS 7.0EG 7.02018-01-10
Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensitive information by reading the MySQL root password from a temporary file before it is removed.
- CVE-2014-5033MEDIUMCVSS v2 6.9EG 6.92014-08-19
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condit…
- CVE-2014-5195HIGHCVSS v2 7.2EG 7.22014-08-07
Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine…
- CVE-2014-5254MEDIUMCVSS 4.7EG 4.72019-11-21
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.
- CVE-2014-5255HIGHCVSS 7.0EG 7.02019-11-21
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254.
- CVE-2014-5332MEDIUMCVSS v2 6.9EG 6.92015-02-06
Race condition in NVMap in NVIDIA Tegra Linux Kernel 3.10 allows local users to gain privileges via a crafted NVMAP_IOC_CREATE IOCTL call, which triggers a use-after-free error, as demonstrated by using a race condition to escape the Chrom…
- CVE-2014-7154MEDIUMCVSS v2 6.1EG 6.12014-10-02
Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.
- CVE-2014-7170LOWCVSS v2 1.9EG 1.92014-12-17
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.
- CVE-2014-7842MEDIUMCVSS v2 4.9EG 4.92014-11-30
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest …
- CVE-2014-7953HIGHCVSS 7.0EG 7.02017-07-07
Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and …
- CVE-2014-8005MEDIUMCVSS v2 5.0EG 5.02014-11-26
Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.
- CVE-2014-8086MEDIUMCVSS 4.7EG 4.72014-10-13
Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation…
- CVE-2014-8640MEDIUMCVSS v2 5.0EG 5.02015-01-14
The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers t…
- CVE-2014-8750MEDIUMCVSS v2 6.5EG 6.52014-10-15
Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be alloc…
- CVE-2014-9150MEDIUMCVSS v2 6.4EG 6.42014-11-30
Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently write to files in arbitrary locations, via an NTFS ju…
- CVE-2014-9529MEDIUMCVSS v2 6.9EG 6.92015-01-09
Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl co…
- CVE-2014-9748HIGHCVSS 8.1EG 8.12020-02-11
The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the locks of other threads, which allows attackers to cause a denial of service (deadlock) or pos…
- CVE-2014-9914HIGHCVSS 7.8EG 7.82017-02-07
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about …
- CVE-2014-9936HIGHCVSS 7.0EG 7.02017-05-16
In TrustZone a time-of-check time-of-use race condition could potentially exist in an authentication routine in all Android releases from CAF using the Linux kernel.
- CVE-2014-9941HIGHCVSS 7.0EG 7.02017-06-06
In the Embedded File System in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.
- CVE-2014-9966HIGHCVSS 7.0EG 7.02017-06-13
In all Android releases from CAF using the Linux kernel, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists in Secure Display.
- CVE-2015-0245LOWCVSS v2 1.9EG 1.92015-02-13
D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by l…
- CVE-2015-0572HIGHCVSS 7.0EG 7.02016-10-10
Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, all…
- CVE-2015-0608HIGHCVSS v2 7.1EG 7.12015-02-12
Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers …
- CVE-2015-0609HIGHCVSS v2 7.1EG 7.12015-02-16
Race condition in the Common Classification Engine (CCE) in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) …
- CVE-2015-0610MEDIUMCVSS v2 4.3EG 4.32015-02-12
Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching …
- CVE-2015-0631HIGHCVSS v2 7.1EG 7.12015-02-21
Race condition in the SSL implementation on Cisco Intrusion Prevention System (IPS) devices allows remote attackers to cause a denial of service by making many management-interface HTTPS connections during the key-regeneration phase of an …
- CVE-2015-0632MEDIUMCVSS v2 5.7EG 5.72015-02-27
Race condition in the Neighbor Discovery (ND) protocol implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service via a flood of Router Solicitation messages on the local network, aka Bug ID CSCuo67770.
- CVE-2015-0654HIGHCVSS v2 7.1EG 7.12015-03-13
Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HT…
- CVE-2015-10067HIGHCVSS 4.6EG 8.12023-01-18
A vulnerability was found in oznetmaster SSharpSmartThreadPool. It has been classified as problematic. This affects an unknown part of the file SSharpSmartThreadPool/SmartThreadPool.cs. The manipulation leads to race condition within a thr…
- CVE-2015-1200LOWCVSS v2 2.1EG 2.12015-01-23
Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before changing the permission to match the original file, which allows local users to bypass the intended access restrictions.
- CVE-2015-1234MEDIUMCVSS v2 6.8EG 6.82015-04-01
Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL…
- CVE-2015-1325HIGHCVSS 7.0EG 7.02017-08-25
Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubun…
- CVE-2015-1340HIGHCVSS 7.0EG 7.02019-04-22
LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode o…
- CVE-2015-1420LOWCVSS v2 1.9EG 1.92015-03-16
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_byte…
- CVE-2015-1862HIGHCVSS 7.0EG 7.02018-02-09
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.
- CVE-2015-1865MEDIUMCVSS 5.1EG 5.12017-09-20
fts.c in coreutils 8.4 allows local users to delete arbitrary files.
- CVE-2015-4170MEDIUMCVSS 4.7EG 4.72016-05-02
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new…
- CVE-2015-5191MEDIUMCVSS 6.7EG 6.72017-07-28
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/…
- CVE-2015-5232HIGHCVSS 8.1EG 8.12017-06-07
Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.
- CVE-2015-5947HIGHCVSS 8.1EG 8.12017-09-06
SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →