Vulnerabilities > Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

DATE CVE VULNERABILITY TITLE RISK
2016-09-26 CVE-2016-7098 Race Condition vulnerability in GNU Wget
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
network
high complexity
gnu CWE-362
8.1
2016-09-18 CVE-2016-0930 Race Condition vulnerability in Pivotal Operations Manager
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist.
network
low complexity
pivotal CWE-362
critical
9.8
2016-08-06 CVE-2016-6516 Race Condition vulnerability in Linux Kernel
Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch" vulnerability.
local
high complexity
linux CWE-362
7.4
2016-08-06 CVE-2016-6480 Race Condition vulnerability in Linux Kernel
Race condition in the ioctl_send_fib function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (out-of-bounds access or system crash) by changing a certain size value, aka a "double fetch" vulnerability.
local
high complexity
linux CWE-362
5.1
2016-08-06 CVE-2016-6156 Race Condition vulnerability in Linux Kernel
Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access) by changing a certain size value, aka a "double fetch" vulnerability.
local
high complexity
linux CWE-362
5.1
2016-08-06 CVE-2016-6136 Race Condition vulnerability in Linux Kernel
Race condition in the audit_log_single_execve_arg function in kernel/auditsc.c in the Linux kernel through 4.7 allows local users to bypass intended character-set restrictions or disrupt system-call auditing by changing a certain string, aka a "double fetch" vulnerability.
local
high complexity
linux CWE-362
4.7
2016-07-22 CVE-2016-4583 Race Condition vulnerability in multiple products
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.
network
high complexity
apple webkitgtk CWE-362
3.1
2016-07-13 CVE-2016-4247 Race Condition vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Race condition in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information via unspecified vectors.
network
high complexity
adobe CWE-362
5.3
2016-07-13 CVE-2016-3258 Race Condition vulnerability in Microsoft products
Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager features, aka "Windows File System Security Feature Bypass."
local
high complexity
microsoft CWE-362
4.7
2016-07-11 CVE-2016-3760 Race Condition vulnerability in Google Android
Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairing that remains present during a session of the primary user, aka internal bug 27410683.
high complexity
google CWE-362
7.5