Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2008-05-02 CVE-2008-1375 Race Condition vulnerability in multiple products
Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.
6.9
2008-04-06 CVE-2008-1684 Race Condition vulnerability in SUN Solaris 10
inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.
local
sun CWE-362
4.7
2008-03-31 CVE-2008-1570 Race Condition vulnerability in Policyd-Weight 0.1.14Beta14
Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs.
6.9
2008-03-18 CVE-2008-0059 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."
network
apple CWE-362
5.8
2008-03-18 CVE-2008-0058 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.
network
apple CWE-362
5.8
2008-03-18 CVE-2008-0055 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.
local
low complexity
apple CWE-362
7.2
2008-02-25 CVE-2008-0933 Race Condition vulnerability in SUN Solaris 10.0
Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_restore.
local
sun CWE-362
4.7
2008-01-18 CVE-2007-6429 Race Condition vulnerability in X.Org Evi, Mit-Shm and Xserver
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.
network
x-org CWE-362
critical
9.3
2008-01-04 CVE-2007-6599 Race Condition vulnerability in multiple products
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.
4.3
2007-12-19 CVE-2007-5847 Race Condition vulnerability in Apple mac OS X 10.4.11
Race condition in the CFURLWriteDataAndPropertiesToResource API in Core Foundation in Apple Mac OS X 10.4.11 creates files with insecure permissions, which might allow local users to obtain sensitive information.
local
low complexity
apple CWE-362
6.6