Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2019-01-09 CVE-2018-16079 Race Condition vulnerability in multiple products
A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
high complexity
google redhat CWE-362
5.3
2019-01-09 CVE-2017-15405 Race Condition vulnerability in Google Chrome
Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a malicious code running with root privileges in cryptohomed in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.
local
high complexity
google CWE-362
7.0
2018-12-20 CVE-2018-5198 Race Condition vulnerability in Wizvera Veraport G3
In Veraport G3 ALL on MacOS, a race condition when calling the Veraport API allow remote attacker to cause arbitrary file download and execution.
network
high complexity
wizvera CWE-362
8.1
2018-12-13 CVE-2018-19489 Race Condition vulnerability in multiple products
v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.
4.7
2018-12-12 CVE-2018-16867 Race Condition vulnerability in multiple products
A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0.
local
high complexity
qemu fedoraproject canonical CWE-362
7.8
2018-12-07 CVE-2018-9519 Race Condition vulnerability in Google Android
In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition.
local
high complexity
google CWE-362
6.4
2018-12-06 CVE-2018-15332 Race Condition vulnerability in F5 Big-Ip Access Policy Manager
The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host in a race condition.
local
high complexity
f5 CWE-362
7.0
2018-11-28 CVE-2018-19370 Race Condition vulnerability in Yoast SEO
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.
network
high complexity
yoast CWE-362
6.6
2018-11-14 CVE-2018-9539 Race Condition vulnerability in Google Android 8.0/8.1/9.0
In the ClearKey CAS descrambler, there is a possible use after free due to a race condition.
local
high complexity
google CWE-362
7.0
2018-11-14 CVE-2018-6061 Race Condition vulnerability in multiple products
A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
high complexity
google redhat debian CWE-362
7.5