Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2017-11-16 CVE-2017-11025 Race Condition vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in the function audio_effects_shared_ioctl(), memory corruption can occur.
local
google CWE-362
4.4
2017-11-07 CVE-2017-2898 Race Condition vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Disney.
8.5
2017-11-06 CVE-2017-16001 Race Condition vulnerability in Hashicorp Vagrant 5.0.1
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
local
low complexity
hashicorp CWE-362
7.2
2017-10-31 CVE-2017-15884 Race Condition vulnerability in Hashicorp Vagrant VMWare Fusion 5.0.0
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
6.9
2017-10-27 CVE-2017-5068 Race Condition vulnerability in multiple products
Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.
network
high complexity
google redhat CWE-362
7.5
2017-10-27 CVE-2017-5061 Race Condition vulnerability in multiple products
A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
high complexity
google redhat CWE-362
5.3
2017-10-23 CVE-2017-7115 Race Condition vulnerability in Apple Iphone OS and Tvos
An issue was discovered in certain Apple products.
network
apple CWE-362
critical
9.3
2017-10-19 CVE-2017-15649 Race Condition vulnerability in Linux Kernel
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a use-after-free, a different vulnerability than CVE-2017-6346.
local
low complexity
linux CWE-362
4.6
2017-10-18 CVE-2017-15588 Race Condition vulnerability in XEN 4.9.0
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
local
xen CWE-362
6.9
2017-10-13 CVE-2017-11823 Race Condition vulnerability in Microsoft Windows 10 and Windows Server 2016
The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Microsoft Windows Security Feature Bypass".
local
low complexity
microsoft CWE-362
7.2