CWE-667 · 664 записей
Improper Locking
CVE этого класса
664 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2025-43510Готовый эксплойт | A memory corruption issue was addressed with improved lock state checking.apple · ipados · CWE-667 | Высокая7,8 | KEV | 0,4 % | 12 дек. 2025 г. |
59В плане | CVE-2021-1782Готовый эксплойт | A race condition was addressed with improved locking.apple · ipados · CWE-667 | Высокая7,0 | KEV | 2,2 % | 2 апр. 2021 г. |
52В плане | CVE-2019-10072Эксплойта нет | The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1apache · tomcat · CWE-667 | Высокая7,5 | — | 73,0 % | 21 июн. 2019 г. |
40В плане | CVE-2020-12658Эксплойта нет | gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c.gssproxy project · gssproxy · CWE-667 | Критическая9,8 | — | 1,8 % | 30 дек. 2020 г. |
39Наблюдать | CVE-2019-5886Эксплойта нет | An issue was discovered in ShopXO 1.2.0.shopxo · shopxo · CWE-667 | Критическая9,8 | — | 1,0 % | 10 янв. 2019 г. |
39Наблюдать | CVE-2026-53049Эксплойта нет | gfs2: add some missing log lockinglinux · linux kernel · CWE-667 | Критическая9,8 | — | 0,6 % | 24 июн. 2026 г. |
39Наблюдать | CVE-2026-64068Эксплойта нет | netfs: Fix missing locking around retry adding new subreqslinux · linux kernel · CWE-667 | Критическая9,8 | — | 0,5 % | 19 июл. 2026 г. |
39Наблюдать | CVE-2026-64067Эксплойта нет | netfs: Fix missing barriers when accessing stream->subrequests locklesslylinux · linux kernel · CWE-667 | Критическая9,8 | — | 0,4 % | 19 июл. 2026 г. |
39Наблюдать | CVE-2021-22530Эксплойта нет | Improper account management vulnerability in NetIQ Advance Authenticationmicrofocus · netiq advanced authentication · CWE-667 | Критическая9,9 | — | 0,2 % | 28 авг. 2024 г. |
35Наблюдать | CVE-2002-1850Proof of concept | mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumptiapache · http server · CWE-667 | Высокая7,5 | — | 17,4 % | 31 дек. 2002 г. |
35Наблюдать | CVE-2020-15674Эксплойта нет | Mozilla developers reported memory safety bugs present in Firefox 80.mozilla · firefox · CWE-667 | Высокая8,8 | — | 0,8 % | 1 окт. 2020 г. |
35Наблюдать | CVE-2026-53071Эксплойта нет | Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsplinux · linux kernel · CWE-667 | Высокая8,8 | — | 0,4 % | 24 июн. 2026 г. |
35Наблюдать | CVE-2026-43215Эксплойта нет | cifs: Fix locking usage for tcon fieldslinux · linux kernel · CWE-667 | Высокая8,8 | — | 0,4 % | 6 мая 2026 г. |
35Наблюдать | CVE-2026-31629Эксплойта нет | nfc: llcp: add missing return after LLCP_CLOSED checkslinux · linux kernel · CWE-667 | Высокая8,8 | — | 0,4 % | 24 апр. 2026 г. |
35Наблюдать | CVE-2026-53358Эксплойта нет | Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()linux · linux kernel · CWE-667 | Высокая8,8 | — | 0,3 % | 2 июл. 2026 г. |
35Наблюдать | CVE-2026-53072Эксплойта нет | Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFERlinux · linux kernel · CWE-667 | Высокая8,8 | — | 0,3 % | 24 июн. 2026 г. |
34Наблюдать | CVE-2009-2699Эксплойта нет | The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as usedapache · http server · CWE-667 | Высокая7,5 | — | 14,2 % | 13 окт. 2009 г. |
34Наблюдать | CVE-2026-21914Эксплойта нет | Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crashjuniper · junos · CWE-667 | Высокая8,7 | — | 0,3 % | 15 янв. 2026 г. |
33Наблюдать | CVE-2004-0174Эксплойта нет | Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to apache · http server · CWE-667 | Высокая7,5 | — | 11,5 % | 4 мая 2004 г. |
33Наблюдать | CVE-2009-4272Эксплойта нет | A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to causlinux · linux kernel · CWE-667 | Высокая7,5 | — | 11,1 % | 27 янв. 2010 г. |
32Наблюдать | CVE-2024-58087Эксплойта нет | ksmbd: fix racy issue from session lookup and expirelinux · linux kernel · CWE-667 | Высокая8,1 | — | 0,5 % | 12 мар. 2025 г. |
32Наблюдать | CVE-2025-58153Эксплойта нет | BIG-IP HSB vulnerabilityf5 · big-ip access policy manager · CWE-667 | Высокая8,2 | — | 0,2 % | 15 окт. 2025 г. |
31Наблюдать | CVE-2020-24606Эксплойта нет | Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handlsquid-cache · squid · CWE-667 | Высокая7,5 | — | 5,0 % | 24 авг. 2020 г. |
31Наблюдать | CVE-2006-5158Эксплойта нет | The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (proclinux · linux kernel · CWE-667 | Высокая7,5 | — | 3,7 % | 5 окт. 2006 г. |
31Наблюдать | CVE-2006-2275Эксплойта нет | Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a lksctp · stream control transmission protocol · CWE-667 | Высокая7,5 | — | 3,6 % | 9 мая 2006 г. |
- CVE-2025-4351061На этой неделе
A memory corruption issue was addressed with improved lock state checking.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 0 %apple · ipados12 дек. 2025 г.
- CVE-2021-178259В плане
A race condition was addressed with improved locking.
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 2 %apple · ipados2 апр. 2021 г.
- CVE-2019-1007252В плане
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1
ВысокаяCVSS 7,5Эксплойта нетEPSS 73 %apache · tomcat21 июн. 2019 г.
- CVE-2020-1265840В плане
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gssproxy project · gssproxy30 дек. 2020 г.
- CVE-2019-588639Наблюдать
An issue was discovered in ShopXO 1.2.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %shopxo · shopxo10 янв. 2019 г.
- CVE-2026-5304939Наблюдать
gfs2: add some missing log locking
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %linux · linux kernel24 июн. 2026 г.
- CVE-2026-6406839Наблюдать
netfs: Fix missing locking around retry adding new subreqs
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %linux · linux kernel19 июл. 2026 г.
- CVE-2026-6406739Наблюдать
netfs: Fix missing barriers when accessing stream->subrequests locklessly
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %linux · linux kernel19 июл. 2026 г.
- CVE-2021-2253039Наблюдать
Improper account management vulnerability in NetIQ Advance Authentication
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %microfocus · netiq advanced authentication28 авг. 2024 г.
- CVE-2002-185035Наблюдать
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumpti
ВысокаяCVSS 7,5Proof of conceptEPSS 17 %apache · http server31 дек. 2002 г.
- CVE-2020-1567435Наблюдать
Mozilla developers reported memory safety bugs present in Firefox 80.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox1 окт. 2020 г.
- CVE-2026-5307135Наблюдать
Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %linux · linux kernel24 июн. 2026 г.
- CVE-2026-4321535Наблюдать
cifs: Fix locking usage for tcon fields
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %linux · linux kernel6 мая 2026 г.
- CVE-2026-3162935Наблюдать
nfc: llcp: add missing return after LLCP_CLOSED checks
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %linux · linux kernel24 апр. 2026 г.
- CVE-2026-5335835Наблюдать
Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %linux · linux kernel2 июл. 2026 г.
- CVE-2026-5307235Наблюдать
Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %linux · linux kernel24 июн. 2026 г.
- CVE-2009-269934Наблюдать
The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used
ВысокаяCVSS 7,5Эксплойта нетEPSS 14 %apache · http server13 окт. 2009 г.
- CVE-2026-2191434Наблюдать
Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %juniper · junos15 янв. 2026 г.
- CVE-2004-017433Наблюдать
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 12 %apache · http server4 мая 2004 г.
- CVE-2009-427233Наблюдать
A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to caus
ВысокаяCVSS 7,5Эксплойта нетEPSS 11 %linux · linux kernel27 янв. 2010 г.
- CVE-2024-5808732Наблюдать
ksmbd: fix racy issue from session lookup and expire
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %linux · linux kernel12 мар. 2025 г.
- CVE-2025-5815332Наблюдать
BIG-IP HSB vulnerability
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %f5 · big-ip access policy manager15 окт. 2025 г.
- CVE-2020-2460631Наблюдать
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handl
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %squid-cache · squid24 авг. 2020 г.
- CVE-2006-515831Наблюдать
The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (proc
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %linux · linux kernel5 окт. 2006 г.
- CVE-2006-227531Наблюдать
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %lksctp · stream control transmission protocol9 мая 2006 г.