Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2017-12-05 CVE-2017-16857 Race Condition vulnerability in Atlassian Bitbucket Auto Unapprove Plugin
It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end.
network
high complexity
atlassian CWE-362
8.5
2017-11-30 CVE-2017-1000405 Race Condition vulnerability in Linux Kernel
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation.
local
high complexity
linux CWE-362
7.0
2017-11-22 CVE-2017-8148 Race Condition vulnerability in Huawei P9 Firmware
Audio driver in P9 smartphones with software The versions before EVA-AL10C00B389 has a denial of service (DoS) vulnerability.
local
high complexity
huawei CWE-362
4.7
2017-11-16 CVE-2017-8279 Race Condition vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, missing race condition protection while updating msg mask table can lead to buffer over-read.
network
low complexity
google CWE-362
7.5
2017-11-16 CVE-2017-11025 Race Condition vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in the function audio_effects_shared_ioctl(), memory corruption can occur.
local
high complexity
google CWE-362
7.0
2017-11-07 CVE-2017-2898 Race Condition vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Disney.
network
high complexity
meetcircle CWE-362
7.5
2017-11-06 CVE-2017-16001 Race Condition vulnerability in Hashicorp Vagrant 5.0.1
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
local
low complexity
hashicorp CWE-362
7.8
2017-10-31 CVE-2017-15884 Race Condition vulnerability in Hashicorp Vagrant VMWare Fusion 5.0.0
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
local
high complexity
hashicorp CWE-362
7.0
2017-10-27 CVE-2017-5068 Race Condition vulnerability in multiple products
Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.
network
high complexity
google redhat CWE-362
7.5
2017-10-27 CVE-2017-5061 Race Condition vulnerability in multiple products
A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
high complexity
google redhat CWE-362
5.3