Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2018-10-26 CVE-2018-15687 Race Condition vulnerability in multiple products
A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files.
local
high complexity
canonical systemd-project CWE-362
7.0
2018-10-17 CVE-2018-7110 Race Condition vulnerability in HPE Service Governance Framework 4.2/4.3
A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3.
network
high complexity
hpe CWE-362
5.9
2018-10-05 CVE-2018-0480 Race Condition vulnerability in Cisco IOS XE 3.6(5)
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition.
high complexity
cisco CWE-362
6.1
2018-10-03 CVE-2018-17972 Race Condition vulnerability in multiple products
An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11.
local
low complexity
linux canonical redhat debian CWE-362
5.5
2018-10-02 CVE-2018-9069 Race Condition vulnerability in multiple products
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
network
high complexity
hp lenovo CWE-362
5.9
2018-09-23 CVE-2018-17364 Race Condition vulnerability in Otcms 3.61
OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.
network
high complexity
otcms CWE-362
8.1
2018-09-20 CVE-2017-18302 Race Condition vulnerability in Qualcomm products
In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions.
local
high complexity
qualcomm CWE-362
4.7
2018-09-19 CVE-2018-5905 Race Condition vulnerability in Google Android
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a race condition while accessing num of clients in DIAG services can lead to out of boundary access.
local
high complexity
google CWE-362
7.0
2018-09-12 CVE-2018-16976 Race Condition vulnerability in Gitolite
Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed.
network
low complexity
gitolite CWE-362
8.1
2018-09-12 CVE-2017-18347 Race Condition vulnerability in ST products
Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup of flash protection.
low complexity
st CWE-362
4.6