Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2020-02-27 CVE-2020-3831 Race Condition vulnerability in Apple Ipados and Iphone OS
A race condition was addressed with improved locking.
network
high complexity
apple CWE-362
7.6
2020-02-21 CVE-2020-9329 Race Condition vulnerability in Gogs
Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
network
gogs CWE-362
4.3
2020-02-20 CVE-2011-0699 Race Condition vulnerability in Linux Kernel 2.6.37
Integer signedness error in the btrfs_ioctl_space_info function in the Linux kernel 2.6.37 allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted slot value.
local
linux CWE-362
6.9
2020-02-19 CVE-2020-3163 Race Condition vulnerability in Cisco Unified Contact Center Enterprise
A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
cisco CWE-362
7.1
2020-02-14 CVE-2019-11215 Race Condition vulnerability in Combodo Itop
In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload.
network
combodo CWE-362
6.8
2020-02-12 CVE-2013-3685 Race Condition vulnerability in Spritesoftware Spritebackup and Spritebud
A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, which could let a local malicious user obtain root privileges.
6.9
2020-02-11 CVE-2014-9748 Race Condition vulnerability in multiple products
The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the locks of other threads, which allows attackers to cause a denial of service (deadlock) or possibly have unspecified other impact by leveraging a race condition.
network
high complexity
libuv nodejs CWE-362
8.1
2020-02-11 CVE-2020-6388 Race Condition vulnerability in Google Chrome
Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-362
8.8
2020-01-31 CVE-2019-3016 Race Condition vulnerability in Linux Kernel
In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest.
local
high complexity
linux CWE-362
4.7
2020-01-28 CVE-2014-3856 Race Condition vulnerability in Fishshell Fish
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
4.4