Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2019-12-03 CVE-2019-19537 Race Condition vulnerability in Linux Kernel
In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9.
local
linux CWE-362
4.7
2019-12-02 CVE-2019-19017 Race Condition vulnerability in Titanhq Webtitan
An issue was discovered in TitanHQ WebTitan before 5.18.
network
titanhq CWE-362
critical
9.3
2019-11-21 CVE-2014-5255 Race Condition vulnerability in multiple products
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.
4.4
2019-11-21 CVE-2014-5254 Race Condition vulnerability in Xcfa Project Xcfa
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.
3.3
2019-11-19 CVE-2016-1000236 Race Condition vulnerability in multiple products
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
network
high complexity
cookie-signature-project debian CWE-362
4.4
2019-11-12 CVE-2019-5228 Race Condition vulnerability in Huawei P30 Firmware
Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability.
network
huawei CWE-362
6.8
2019-11-12 CVE-2019-1416 Race Condition vulnerability in Microsoft products
An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.
4.4
2019-11-09 CVE-2009-4011 Race Condition vulnerability in Dtc-Xen Project Dtc-Xen
dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX user on the dom0, and then access a potentially reuse an already opened VPS console.
6.8
2019-11-06 CVE-2019-10529 Race Condition vulnerability in Qualcomm products
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
network
qualcomm CWE-362
critical
9.3
2019-11-06 CVE-2006-4245 Race Condition vulnerability in multiple products
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
6.8