Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2021-04-07 CVE-2020-25584 Race Condition vulnerability in Freebsd
In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, a superuser inside a FreeBSD jail configured with the non-default allow.mount permission could cause a race condition between the lookup of ".." and remounting a filesystem, allowing access to filesystem hierarchy outside of the jail.
local
high complexity
freebsd CWE-362
7.5
2021-04-02 CVE-2021-1806 Race Condition vulnerability in Apple mac OS X and Macos
A race condition was addressed with additional validation.
local
high complexity
apple CWE-362
7.0
2021-04-02 CVE-2020-27921 Race Condition vulnerability in Apple mac OS X
A race condition was addressed with improved state handling.
local
high complexity
apple CWE-362
7.0
2021-03-30 CVE-2021-25158 Race Condition vulnerability in multiple products
A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below.
network
high complexity
arubanetworks siemens CWE-362
5.9
2021-03-26 CVE-2021-29265 Race Condition vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.11.7.
local
high complexity
linux debian CWE-362
4.7
2021-03-26 CVE-2020-25582 Race Condition vulnerability in Freebsd 11.4/12.2
In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.
network
low complexity
freebsd CWE-362
8.7
2021-03-26 CVE-2020-25581 Race Condition vulnerability in Freebsd 11.4/12.2
In FreeBSD 12.2-STABLE before r369312, 11.4-STABLE before r369313, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 due to a race condition in the jail_remove(2) implementation, it may fail to kill some of the processes.
network
high complexity
freebsd CWE-362
7.5
2021-03-22 CVE-2021-28964 Race Condition vulnerability in multiple products
A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8.
local
high complexity
linux fedoraproject debian netapp CWE-362
4.7
2021-03-12 CVE-2021-26569 Race Condition vulnerability in Synology Diskstation Manager
Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.
network
high complexity
synology CWE-362
8.1
2021-03-10 CVE-2021-0387 Race Condition vulnerability in Google Android 11.0
In FindQuotaDeviceForUuid of QuotaUtils.cpp, there is a possible use-after-free due to a race condition.
local
high complexity
google CWE-362
6.4