Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-8565 Race Condition vulnerability in Apple mac OS X
A race condition was addressed with additional validation.
local
high complexity
apple CWE-362
7.0
2019-12-18 CVE-2019-6236 Race Condition vulnerability in Apple Icloud
A race condition existed during the installation of iCloud for Windows.
network
high complexity
apple CWE-362
7.5
2019-12-18 CVE-2019-6232 Race Condition vulnerability in Apple Icloud
A race condition existed during the installation of iTunes for Windows.
network
high complexity
apple CWE-362
7.5
2019-12-16 CVE-2019-16779 Race Condition vulnerability in multiple products
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket.
network
high complexity
excon-project opensuse debian CWE-362
5.9
2019-12-15 CVE-2014-3701 Race Condition vulnerability in Redhat Edeploy and Jboss Enterprise web Server
eDeploy has tmp file race condition flaws
network
high complexity
redhat CWE-362
8.1
2019-12-11 CVE-2019-19580 Race Condition vulnerability in multiple products
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421.
network
high complexity
xen fedoraproject CWE-362
6.6
2019-12-06 CVE-2019-2219 Race Condition vulnerability in Google Android 10.0/9.0
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass.
local
high complexity
google CWE-362
4.7
2019-12-03 CVE-2019-19537 Race Condition vulnerability in Linux Kernel
In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9.
high complexity
linux CWE-362
4.2
2019-11-21 CVE-2014-5255 Race Condition vulnerability in multiple products
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.
local
high complexity
xcfa-project debian CWE-362
7.0
2019-11-21 CVE-2014-5254 Race Condition vulnerability in Xcfa Project Xcfa
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.
local
high complexity
xcfa-project CWE-362
4.7