Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-6232 Race Condition vulnerability in Apple Icloud
A race condition existed during the installation of iTunes for Windows.
network
high complexity
apple CWE-362
7.6
2019-12-16 CVE-2019-16779 Race Condition vulnerability in multiple products
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket.
4.3
2019-12-15 CVE-2014-3701 Race Condition vulnerability in Redhat Edeploy and Jboss Enterprise web Server
eDeploy has tmp file race condition flaws
network
redhat CWE-362
critical
9.3
2019-12-11 CVE-2019-19580 Race Condition vulnerability in multiple products
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421.
network
high complexity
xen fedoraproject CWE-362
6.6
2019-12-06 CVE-2019-2219 Race Condition vulnerability in Google Android 10.0/9.0
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass.
local
google CWE-362
4.7
2019-12-03 CVE-2019-19537 Race Condition vulnerability in Linux Kernel
In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9.
local
linux CWE-362
4.7
2019-12-02 CVE-2019-19017 Race Condition vulnerability in Titanhq Webtitan
An issue was discovered in TitanHQ WebTitan before 5.18.
network
titanhq CWE-362
critical
9.3
2019-11-21 CVE-2014-5255 Race Condition vulnerability in multiple products
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.
4.4
2019-11-21 CVE-2014-5254 Race Condition vulnerability in Xcfa Project Xcfa
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.
3.3
2019-11-19 CVE-2016-1000236 Race Condition vulnerability in multiple products
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
network
high complexity
cookie-signature-project debian CWE-362
4.4