Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2019-03-15 CVE-2018-18253 Race Condition vulnerability in Capmon Access Manager 5.4.1.1005
An issue was discovered in CapMon Access Manager 5.4.1.1005.
local
high complexity
capmon CWE-362
7.0
2019-03-12 CVE-2019-9710 Race Condition vulnerability in Webargs Project Webargs
An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products.
network
high complexity
webargs-project CWE-362
8.1
2019-03-07 CVE-2018-18808 Race Condition vulnerability in Tibco products
The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability that may allow any users with domain save privileges to gain superuser privileges.
network
high complexity
tibco CWE-362
7.5
2019-02-11 CVE-2018-9586 Race Condition vulnerability in Google Android
In run of InstallPackageTask.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, it is possible that package verification is turned off and remains off due to a race condition.
local
high complexity
google CWE-362
7.0
2019-02-11 CVE-2019-7718 Race Condition vulnerability in Metinfo
An issue was discovered in Metinfo 6.x.
network
high complexity
metinfo CWE-362
8.1
2019-02-04 CVE-2019-3461 Race Condition vulnerability in Debian Linux and Tmpreaper
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation.
local
high complexity
debian CWE-362
7.0
2019-02-01 CVE-2016-10741 Race Condition vulnerability in multiple products
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.
local
high complexity
linux debian CWE-362
4.7
2019-01-18 CVE-2018-11998 Race Condition vulnerability in Qualcomm products
While processing a packet decode request in MQTT, Race condition can occur leading to an out-of-bounds access in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 427, SD 435, SD 450, SD 625, SD 636, SD 835, SDA660, SDM630, SDM660, Snapdragon_High_Med_2016
high complexity
qualcomm CWE-362
7.5
2019-01-11 CVE-2019-6133 Race Condition vulnerability in multiple products
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached.
local
high complexity
polkit-project debian redhat canonical CWE-362
6.7
2019-01-09 CVE-2018-6158 Race Condition vulnerability in multiple products
A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
high complexity
google debian redhat CWE-362
7.5