Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2009-01-26 CVE-2009-0268 Race Condition vulnerability in SUN Opensolaris and Solaris
Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.
local
low complexity
sun CWE-362
4.9
2008-12-01 CVE-2008-5303 Race Condition vulnerability in Perl File::Path 1.08
Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827.
local
perl CWE-362
6.9
2008-12-01 CVE-2008-5302 Race Condition vulnerability in Perl File::Path 1.08/2.07
Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827.
local
perl CWE-362
6.9
2008-11-25 CVE-2008-4229 Race Condition vulnerability in Apple Iphone OS
Race condition in the Passcode Lock feature in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.0 through 2.1 allows physically proximate attackers to remove the lock and launch arbitrary applications by restoring the device from a backup.
local
high complexity
apple CWE-362
3.7
2008-11-21 CVE-2008-5182 Race Condition vulnerability in Linux Kernel
The inotify functionality in Linux kernel 2.6 before 2.6.28-rc5 might allow local users to gain privileges via unknown vectors related to race conditions in inotify watch removal and umount.
local
linux CWE-362
6.9
2008-11-12 CVE-2008-5044 Race Condition vulnerability in Microsoft Windows Server 2003 and Windows Vista
Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.
local
high complexity
microsoft CWE-362
4.0
2008-11-10 CVE-2008-5009 Race Condition vulnerability in SUN Solstice X.25 9.2
Race condition in the s_xout kernel module in Sun Solstice X.25 9.2, when running on a multiple CPU machine, allows local users to cause a denial of service (panic) via vectors involving reading the /dev/xty file.
local
high complexity
sun CWE-362
4.0
2008-10-10 CVE-2008-3646 Race Condition vulnerability in Apple mac OS X 10.5.5
The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail is sent from a local command-line tool, which allows remote attackers to send mail to local Mac OS X users.
network
apple CWE-362
6.8
2008-07-01 CVE-2008-2958 Race Condition vulnerability in Checkinstall 1.6.1
Race condition in (1) checkinstall 1.6.1 and (2) installwatch allows local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on temporary working directories.
4.4
2008-07-01 CVE-2008-2311 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.
network
high complexity
apple CWE-362
7.6