CWE-667
669 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-667page 1 of 14
- CVE-2000-0338MEDIUMCVSS 5.5EG 5.52000-04-23
Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.
- CVE-2000-1198MEDIUMCVSS 5.5EG 5.52001-08-31
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.
- CVE-2001-0682MEDIUMCVSS 5.5EG 5.52001-08-29
ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.
- CVE-2002-0051HIGHCVSS 7.8EG 7.82002-04-04
Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.
- CVE-2002-1850HIGHCVSS 7.5EG 7.52002-12-31
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write…
- CVE-2002-1869LOWCVSS 3.3EG 3.32002-12-31
Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Micro…
- CVE-2002-1914MEDIUMCVSS 5.5EG 5.52002-12-31
dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file.
- CVE-2002-1915MEDIUMCVSS 5.5EG 5.52002-12-31
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
- CVE-2004-0174HIGHCVSS 7.5EG 7.52004-05-04
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-acces…
- CVE-2005-2456MEDIUMCVSS 5.5EG 5.52005-08-04
Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFR…
- CVE-2005-3106MEDIUMCVSS 4.7EG 4.72005-09-30
Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that h…
- CVE-2005-3847MEDIUMCVSS 5.5EG 5.52005-11-27
The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is …
- CVE-2006-2275HIGHCVSS 7.5EG 7.52006-05-09
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of …
- CVE-2006-2374MEDIUMCVSS 5.5EG 5.52006-06-13
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with th…
- CVE-2006-4342MEDIUMCVSS 5.5EG 5.52006-10-17
The kernel in Red Hat Enterprise Linux 3, when running on SMP systems, allows local users to cause a denial of service (deadlock) by running the shmat function on an shm at the same time that shmctl is removing that shm (IPC_RMID), which p…
- CVE-2006-5158HIGHCVSS 7.5EG 7.52006-10-05
The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null …
- CVE-2008-4302MEDIUMCVSS 5.5EG 5.52008-09-29
fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to c…
- CVE-2009-0935MEDIUMCVSS 5.5EG 5.52009-03-18
The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, which causes the device…
- CVE-2009-1243MEDIUMCVSS 5.5EG 5.52009-04-06
net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain incorrect circumstances, which allows local users to cause a denial of service (panic) by reading zero bytes from the /proc/net/udp file and unspecifi…
- CVE-2009-1388MEDIUMCVSS 5.5EG 5.52009-07-05
The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the…
- CVE-2009-1961MEDIUMCVSS 4.7EG 4.72009-06-08
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (pre…
- CVE-2009-2699HIGHCVSS 7.5EG 7.52009-10-13
The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which…
- CVE-2009-2857MEDIUMCVSS 5.5EG 5.52009-08-19
The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and sys…
- CVE-2009-4272HIGHCVSS 7.5EG 7.52010-01-27
A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash…
- CVE-2010-4210HIGHCVSS 7.8EG 7.82010-11-22
The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations…
- CVE-2018-0228HIGHCVSS 8.6EG 8.62018-04-19
A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (Do…
- CVE-2018-0381MEDIUMCVSS 6.8EG 6.82018-10-17
A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerabilit…
- CVE-2018-1000127HIGHCVSS 7.5EG 7.52018-03-13
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be …
- CVE-2018-15390MEDIUMCVSS 6.8EG 6.82018-10-05
A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vuln…
- CVE-2018-9344HIGHCVSS 7.8EG 7.82024-11-19
In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex…
- CVE-2019-10072HIGHCVSS 7.5EG 7.52019-06-21
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (s…
- CVE-2019-10494HIGHCVSS 8.1EG 8.12019-12-12
Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IO…
- CVE-2019-11599HIGHCVSS 7.0EG 7.02019-04-29
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of se…
- CVE-2019-13762LOWCVSS 3.3EG 3.32019-12-10
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.
- CVE-2019-14091HIGHCVSS 7.8EG 7.82020-06-22
Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, …
- CVE-2019-14763MEDIUMCVSS 5.5EG 5.52019-08-07
In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock with f_hid.
- CVE-2019-14898HIGHCVSS 7.0EG 7.02020-05-08
The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a …
- CVE-2019-15513HIGHCVSS 7.5EG 7.52019-08-23
An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a lon…
- CVE-2019-1649MEDIUMCVSS 6.7EG 6.72019-05-13
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. …
- CVE-2019-1732MEDIUMCVSS 6.4EG 6.42019-05-15
A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race condition to corrupt l…
- CVE-2019-17343MEDIUMCVSS 6.8EG 6.82019-10-08
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.
- CVE-2019-2025HIGHCVSS 7.8EG 7.82019-06-19
In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2019-2050HIGHCVSS 7.8EG 7.82019-05-08
In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- CVE-2019-2119MEDIUMCVSS 5.5EG 5.52019-07-08
In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This could lead to local information disclosure of protected data with no additional execution privileges needed. User inte…
- CVE-2019-2174HIGHCVSS 7.8EG 7.82019-09-05
In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution pr…
- CVE-2019-3901MEDIUMCVSS 4.7EG 4.72019-04-22
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specif…
- CVE-2019-5886CRITICALCVSS 9.8EG 9.82019-01-10
An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. The attacker can write arbitrary code to…
- CVE-2019-6156LOWCVSS 3.3EG 3.32019-04-10
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that …
- CVE-2019-6321HIGHCVSS 7.2EG 7.22019-05-29
HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is disabled b…
- CVE-2019-6322MEDIUMCVSS 6.8EG 6.82019-05-29
HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is enabled by…
Map vulnerabilities like CWE-667 to your infrastructure
EchelonGraph correlates every CVE — across CWE-667 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →