Vulnerabilities > Improper Locking

DATE CVE VULNERABILITY TITLE RISK
2023-02-28 CVE-2023-20939 Improper Locking vulnerability in Google Android 12.0/12.1/13.0
In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to improper locking.
local
low complexity
google CWE-667
7.8
2023-02-06 CVE-2023-20618 Improper Locking vulnerability in Google Android 11.0/12.0/13.0
In vcu, there is a possible memory corruption due to improper locking.
local
low complexity
google CWE-667
6.7
2023-02-06 CVE-2023-20619 Improper Locking vulnerability in Google Android 11.0/12.0/13.0
In vcu, there is a possible memory corruption due to improper locking.
local
low complexity
google CWE-667
6.7
2023-01-26 CVE-2023-20928 Improper Locking vulnerability in Google Android
In binder_vma_close of binder.c, there is a possible use after free due to improper locking.
local
low complexity
google CWE-667
7.8
2023-01-04 CVE-2022-48216 Improper Locking vulnerability in Uniswap Universal Router Firmware 1.0.0/1.0.1
Uniswap Universal Router before 1.1.0 mishandles reentrancy.
network
high complexity
uniswap CWE-667
7.5
2022-12-26 CVE-2021-43395 Improper Locking vulnerability in multiple products
An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923.
5.5
2022-12-16 CVE-2022-20566 Improper Locking vulnerability in Google Android
In l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking.
local
low complexity
google CWE-667
7.8
2022-12-13 CVE-2022-3996 Improper Locking vulnerability in Openssl
If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively.
network
low complexity
openssl CWE-667
7.5
2022-12-07 CVE-2022-42328 Improper Locking vulnerability in multiple products
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free the SKB of a packet dropped due to the XSA-392 handling (CVE-2022-42328).
local
low complexity
linux debian CWE-667
5.5
2022-12-07 CVE-2022-42329 Improper Locking vulnerability in multiple products
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free the SKB of a packet dropped due to the XSA-392 handling (CVE-2022-42328).
local
low complexity
linux debian CWE-667
5.5