Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2023-06-23 CVE-2023-32413 Race Condition vulnerability in Apple products
A race condition was addressed with improved state handling.
local
high complexity
apple CWE-362
7.0
2023-06-15 CVE-2023-21095 Race Condition vulnerability in Google Android 12.1/13.0
In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a race condition.
local
high complexity
google CWE-362
4.7
2023-06-02 CVE-2023-29537 Race Condition vulnerability in Mozilla Firefox and Focus
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code.
network
high complexity
mozilla CWE-362
7.5
2023-05-30 CVE-2023-33974 Race Condition vulnerability in Riot-Os Riot
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames.
network
high complexity
riot-os CWE-362
5.9
2023-05-29 CVE-2023-30571 Race Condition vulnerability in Libarchive
Libarchive through 3.6.2 can cause directories to have world-writable permissions.
local
high complexity
libarchive CWE-362
5.3
2023-05-18 CVE-2023-33203 Race Condition vulnerability in multiple products
The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.
high complexity
linux redhat CWE-362
6.4
2023-05-10 CVE-2023-32570 Race Condition vulnerability in multiple products
VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.
network
high complexity
videolan fedoraproject CWE-362
5.9
2023-05-09 CVE-2023-28125 Race Condition vulnerability in Ivanti Avalanche
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
network
high complexity
ivanti CWE-362
5.9
2023-05-09 CVE-2023-28126 Race Condition vulnerability in Ivanti Avalanche
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
network
high complexity
ivanti CWE-362
5.9
2023-05-09 CVE-2023-24899 Race Condition vulnerability in Microsoft products
Windows Graphics Component Elevation of Privilege Vulnerability
local
high complexity
microsoft CWE-362
7.0