Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2009-05-26 CVE-2009-1786 Race Condition vulnerability in IBM AIX 5.3/6.1
The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.
local
ibm CWE-362
6.9
2009-04-03 CVE-2008-6598 Race Condition vulnerability in Sangoma Wanpipe
Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."
network
low complexity
sangoma CWE-362
critical
10.0
2009-04-02 CVE-2009-1238 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.
local
low complexity
apple CWE-362
7.2
2009-04-01 CVE-2009-1215 Race Condition vulnerability in GNU Screen 4.0.3
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
local
gnu CWE-362
1.9
2009-04-01 CVE-2009-1207 Race Condition vulnerability in SUN Opensolaris and Solaris
Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.
local
sun CWE-362
4.4
2009-03-25 CVE-2009-0784 Race Condition vulnerability in multiple products
Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.
6.3
2009-03-12 CVE-2009-0875 Race Condition vulnerability in SUN Opensolaris and Solaris
Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.
local
sun CWE-362
6.9
2009-02-19 CVE-2008-4392 Race Condition vulnerability in D.J.Bernstein Djbdns 1.05
dnscache in Daniel J.
network
low complexity
d-j-bernstein CWE-362
6.4
2009-02-12 CVE-2009-0142 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of service (infinite loop) via unspecified vectors related to "file enumeration logic."
local
apple CWE-362
1.9
2009-01-28 CVE-2009-0320 Race Condition vulnerability in Microsoft products
Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."
local
high complexity
microsoft CWE-362
4.0