CWE-362 · 2,502 records
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVEs in this class
2,502 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-36884Weaponized | Windows Search Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-362 | High7.5 | KEV | 98.9% | Jul 11, 2023 |
83Now | CVE-2016-5195Weaponized | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect halinux · linux kernel · CWE-362 | High7.0 | KEV | 83.5% | Nov 10, 2016 |
72This week | CVE-2021-21166Weaponized | Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTMgoogle · chrome · CWE-362 | High8.8 | KEV | 24.0% | Mar 9, 2021 |
64This week | CVE-2020-6820Weaponized | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | High8.1 | KEV | 7.1% | Apr 24, 2020 |
63This week | CVE-2022-26904Weaponized | Windows User Profile Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-362 | High7.0 | KEV | 16.9% | Apr 15, 2022 |
63This week | CVE-2020-6819Weaponized | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | High8.1 | KEV | 3.0% | Apr 24, 2020 |
60This week | CVE-2025-62215Weaponized | Windows Kernel Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-362 | High7.0 | KEV | 6.0% | Nov 11, 2025 |
59Plan | CVE-2014-0196Weaponized | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO linux · linux kernel · CWE-362 | Medium5.5 | KEV | 22.5% | May 7, 2014 |
58Plan | CVE-2024-27983Proof of concept | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 fnodejs · node · CWE-362 | High8.2 | — | 87.2% | Apr 8, 2024 |
55Plan | CVE-2021-0920Weaponized | In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition.linux · linux kernel · CWE-362 | Medium6.4 | KEV | 0.9% | Dec 15, 2021 |
55Plan | CVE-2021-25395Weaponized | A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilsamsung · android · CWE-362 | Medium6.4 | KEV | 0.4% | Jun 11, 2021 |
53Plan | CVE-2014-0226Proof of concept | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-bapache · http server · CWE-362 | Medium6.8 | — | 85.7% | Jul 20, 2014 |
52Plan | CVE-2025-39964Weaponized | crypto: af_alg - Disallow concurrent writes in af_alg_sendmsglinux · linux kernel · CWE-362 | Medium5.5 | KEV | 1.3% | Oct 13, 2025 |
51Plan | CVE-2018-15473Weaponized | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after openbsd · openssh · CWE-362 | Medium5.3 | — | 98.6% | Aug 17, 2018 |
46Plan | CVE-2010-0017Weaponized | Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-mmicrosoft · windows 7 · CWE-362 | Critical9.3 | — | 30.8% | Feb 10, 2010 |
45Plan | CVE-2007-0099No exploit | Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remotemicrosoft · xml core services · CWE-362 | Critical9.3 | — | 25.7% | Jan 8, 2007 |
44Plan | CVE-2010-0489No exploit | Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTMLmicrosoft · internet explorer · CWE-362 | Critical9.3 | — | 23.7% | Mar 31, 2010 |
44Plan | CVE-2015-8556Proof of concept | Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.qemu · qemu · CWE-362 | Critical10.0 | — | 13.4% | Mar 24, 2017 |
43Plan | CVE-2010-2558No exploit | Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memicrosoft · internet explorer · CWE-362 | Critical9.3 | — | 21.0% | Aug 11, 2010 |
42Plan | CVE-2022-46689Weaponized | A race condition was addressed with additional validation.apple · safari · CWE-362 | High7.0 | — | 46.1% | Dec 15, 2022 |
42Plan | CVE-2020-7457Weaponized | In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before pfreebsd · freebsd · CWE-362 | High8.1 | — | 33.1% | Jul 9, 2020 |
41Plan | CVE-2014-0703No exploit | Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the cisco · wireless lan controller software · CWE-362 | Critical10.0 | — | 2.0% | Mar 6, 2014 |
40Plan | CVE-2021-32810No exploit | Data race in crossbeam-dequecrossbeam project · crossbeam · CWE-362 | Critical9.8 | — | 1.9% | Aug 2, 2021 |
40Plan | CVE-2008-6598No exploit | Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."sangoma · wanpipe · CWE-362 | Critical10.0 | — | 1.1% | Apr 3, 2009 |
40Plan | CVE-2010-1228No exploit | Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.google · chrome · CWE-362 | Critical10.0 | — | 0.8% | Apr 1, 2010 |
- CVE-2023-3688490Now
Windows Search Remote Code Execution Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 99%microsoft · windows 10 1507Jul 11, 2023
- CVE-2016-519583Now
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha
HighCVSS 7.0KEVWeaponizedEPSS 84%linux · linux kernelNov 10, 2016
- CVE-2021-2116672This week
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM
HighCVSS 8.8KEVWeaponizedEPSS 24%google · chromeMar 9, 2021
- CVE-2020-682064This week
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.
HighCVSS 8.1KEVWeaponizedEPSS 7%mozilla · firefoxApr 24, 2020
- CVE-2022-2690463This week
Windows User Profile Service Elevation of Privilege Vulnerability
HighCVSS 7.0KEVWeaponizedEPSS 17%microsoft · windows 10 1507Apr 15, 2022
- CVE-2020-681963This week
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.
HighCVSS 8.1KEVWeaponizedEPSS 3%mozilla · firefoxApr 24, 2020
- CVE-2025-6221560This week
Windows Kernel Elevation of Privilege Vulnerability
HighCVSS 7.0KEVWeaponizedEPSS 6%microsoft · windows 10 1809Nov 11, 2025
- CVE-2014-019659Plan
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO
MediumCVSS 5.5KEVWeaponizedEPSS 22%linux · linux kernelMay 7, 2014
- CVE-2024-2798358Plan
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 f
HighCVSS 8.2Proof of conceptEPSS 87%nodejs · nodeApr 8, 2024
- CVE-2021-092055Plan
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition.
MediumCVSS 6.4KEVWeaponizedEPSS 1%linux · linux kernelDec 15, 2021
- CVE-2021-2539555Plan
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privil
MediumCVSS 6.4KEVWeaponizedEPSS 0%samsung · androidJun 11, 2021
- CVE-2014-022653Plan
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-b
MediumCVSS 6.8Proof of conceptEPSS 86%apache · http serverJul 20, 2014
- CVE-2025-3996452Plan
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
MediumCVSS 5.5KEVWeaponizedEPSS 1%linux · linux kernelOct 13, 2025
- CVE-2018-1547351Plan
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after
MediumCVSS 5.3WeaponizedEPSS 99%openbsd · opensshAug 17, 2018
- CVE-2010-001746Plan
Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-m
CriticalCVSS 9.3WeaponizedEPSS 31%microsoft · windows 7Feb 10, 2010
- CVE-2007-009945Plan
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote
CriticalCVSS 9.3No exploitEPSS 26%microsoft · xml core servicesJan 8, 2007
- CVE-2010-048944Plan
Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML
CriticalCVSS 9.3No exploitEPSS 24%microsoft · internet explorerMar 31, 2010
- CVE-2015-855644Plan
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
CriticalCVSS 10.0Proof of conceptEPSS 13%qemu · qemuMar 24, 2017
- CVE-2010-255843Plan
Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (me
CriticalCVSS 9.3No exploitEPSS 21%microsoft · internet explorerAug 11, 2010
- CVE-2022-4668942Plan
A race condition was addressed with additional validation.
HighCVSS 7.0WeaponizedEPSS 46%apple · safariDec 15, 2022
- CVE-2020-745742Plan
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p
HighCVSS 8.1WeaponizedEPSS 33%freebsd · freebsdJul 9, 2020
- CVE-2014-070341Plan
Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the
CriticalCVSS 10.0No exploitEPSS 2%cisco · wireless lan controller softwareMar 6, 2014
- CVE-2021-3281040Plan
Data race in crossbeam-deque
CriticalCVSS 9.8No exploitEPSS 2%crossbeam project · crossbeamAug 2, 2021
- CVE-2008-659840Plan
Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."
CriticalCVSS 10.0No exploitEPSS 1%sangoma · wanpipeApr 3, 2009
- CVE-2010-122840Plan
Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 1%google · chromeApr 1, 2010