Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2017-10-02 CVE-2017-14955 Race Condition vulnerability in Checkmk
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
network
high complexity
checkmk CWE-362
5.9
2017-09-26 CVE-2017-14748 Race Condition vulnerability in Blizzard Overwatch 1.15.0.2
Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season bans and SR losses for other users) by leaving a competitive match at a specific time during the initial loading of that match.
network
high complexity
blizzard CWE-362
5.3
2017-09-25 CVE-2017-1346 Race Condition vulnerability in IBM Business Process Manager
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan.
local
high complexity
ibm CWE-362
2.5
2017-09-21 CVE-2017-9677 Race Condition vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, while it is not protected with locks.
local
low complexity
google CWE-362
7.8
2017-09-21 CVE-2017-8281 Race Condition vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
local
high complexity
google CWE-362
4.7
2017-09-20 CVE-2015-1865 Race Condition vulnerability in GNU Coreutils 8.4
fts.c in coreutils 8.4 allows local users to delete arbitrary files.
local
high complexity
gnu CWE-362
4.7
2017-09-15 CVE-2017-14483 Race Condition vulnerability in Gentoo Dev-Python-Flower
flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file ownership to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command.
local
low complexity
gentoo CWE-362
5.5
2017-09-14 CVE-2015-7553 Race Condition vulnerability in Redhat Enterprise Linux, Enterprise MRG and Kernel-Rt
Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink sockets.
local
high complexity
redhat CWE-362
4.7
2017-09-13 CVE-2017-0161 Race Condition vulnerability in Microsoft products
The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to maintain certain sequencing requirements, aka "NetBIOS Remote Code Execution Vulnerability".
network
high complexity
microsoft CWE-362
8.1
2017-09-12 CVE-2017-14317 Race Condition vulnerability in XEN
A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x.
local
high complexity
xen CWE-362
5.6