Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2009-10-06 CVE-2009-3527 Race Condition vulnerability in Freebsd 6.3/6.4
Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference or memory corruption.
6.9
2009-09-29 CVE-2009-3447 Race Condition vulnerability in Radactive I-Load
Unrestricted file upload vulnerability in RADactive I-Load before 2008.2.5.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, and then sending a request for a predictable filename during a short time window.
network
radactive CWE-362
6.8
2009-09-10 CVE-2009-2794 Race Condition vulnerability in Apple Iphone OS
The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.
local
low complexity
apple CWE-362
4.6
2009-09-08 CVE-2009-3110 Race Condition vulnerability in Symantec Altiris Deployment Solution
Race condition in the file transfer functionality in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 allows remote attackers to read sensitive files and prevent client updates by connecting to the file transfer port before the expected client does.
network
symantec CWE-362
5.8
2009-08-10 CVE-2009-2724 Race Condition vulnerability in SUN Java SE
Race condition in the java.lang package in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, related to a "3Y Race condition in reflection checks."
network
sun CWE-362
critical
9.3
2009-07-29 CVE-2009-2644 Race Condition vulnerability in SUN Opensolaris and Solaris
Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to "pathnames for invalid fds."
local
low complexity
sun CWE-362
4.9
2009-07-05 CVE-2009-2314 Race Condition vulnerability in SUN Lightweight Availability Collection Tool 3.0
Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to overwrite arbitrary files via unspecified vectors.
local
low complexity
sun CWE-362
2.1
2009-06-19 CVE-2009-2135 Race Condition vulnerability in SUN Opensolaris and Solaris
Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the port_dissociate and close functions.
local
low complexity
sun CWE-362
4.9
2009-06-10 CVE-2009-1707 Race Condition vulnerability in Apple Safari
Race condition in the Reset Safari implementation in Apple Safari before 4.0 on Windows might allow local users to read stored web-site passwords via unspecified vectors.
local
high complexity
apple CWE-362
1.2
2009-06-01 CVE-2008-6819 Race Condition vulnerability in Microsoft Windows 2003 Server and Windows Vista
win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084.
4.7