Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2019-09-27 CVE-2019-2188 Race Condition vulnerability in Google Android 10.0
In the Easel driver, there is possible memory corruption due to race conditions.
local
google CWE-362
6.9
2019-09-27 CVE-2019-11736 Race Condition vulnerability in Mozilla Firefox
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access.
4.4
2019-09-25 CVE-2019-13627 Race Condition vulnerability in multiple products
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library.
2.6
2019-09-16 CVE-2019-11184 Race Condition vulnerability in multiple products
A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.
high complexity
intel netapp CWE-362
4.8
2019-09-16 CVE-2019-16354 Race Condition vulnerability in Beego 1.10.0
The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition involving file creation within a directory with weak permissions.
local
beego CWE-362
1.9
2019-09-09 CVE-2019-11546 Race Condition vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2.
network
gitlab CWE-362
3.5
2019-09-06 CVE-2019-9450 Race Condition vulnerability in Google Android
In the Android kernel in the FingerTipS touchscreen driver there is a possible memory corruption due to a race condition.
local
google CWE-362
4.4
2019-08-30 CVE-2019-5612 Race Condition vulnerability in multiple products
In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, the kernel driver for /dev/midistat implements a read handler that is not thread-safe.
network
low complexity
freebsd netapp CWE-362
7.5
2019-08-20 CVE-2019-2121 Race Condition vulnerability in Google Android 9.0
In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition.
local
google CWE-362
6.9
2019-08-07 CVE-2016-10798 Race Condition vulnerability in Cpanel
cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).
network
cpanel CWE-362
4.9