Skip to content
Noroxi

CWE-362 · 2,502 records

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVEs in this class

2,502 records

  • Windows Search Remote Code Execution Vulnerability

    HighCVSS 7.5KEVWeaponizedEPSS 99%

    microsoft · windows 10 1507Jul 11, 2023

  • Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha

    HighCVSS 7.0KEVWeaponizedEPSS 84%

    linux · linux kernelNov 10, 2016

  • CVE-2021-21166
    72This week

    Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM

    HighCVSS 8.8KEVWeaponizedEPSS 24%

    google · chromeMar 9, 2021

  • CVE-2020-6820
    64This week

    Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.

    HighCVSS 8.1KEVWeaponizedEPSS 7%

    mozilla · firefoxApr 24, 2020

  • CVE-2022-26904
    63This week

    Windows User Profile Service Elevation of Privilege Vulnerability

    HighCVSS 7.0KEVWeaponizedEPSS 17%

    microsoft · windows 10 1507Apr 15, 2022

  • CVE-2020-6819
    63This week

    Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.

    HighCVSS 8.1KEVWeaponizedEPSS 3%

    mozilla · firefoxApr 24, 2020

  • CVE-2025-62215
    60This week

    Windows Kernel Elevation of Privilege Vulnerability

    HighCVSS 7.0KEVWeaponizedEPSS 6%

    microsoft · windows 10 1809Nov 11, 2025

  • The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO

    MediumCVSS 5.5KEVWeaponizedEPSS 22%

    linux · linux kernelMay 7, 2014

  • An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 f

    HighCVSS 8.2Proof of conceptEPSS 87%

    nodejs · nodeApr 8, 2024

  • In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition.

    MediumCVSS 6.4KEVWeaponizedEPSS 1%

    linux · linux kernelDec 15, 2021

  • A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privil

    MediumCVSS 6.4KEVWeaponizedEPSS 0%

    samsung · androidJun 11, 2021

  • Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-b

    MediumCVSS 6.8Proof of conceptEPSS 86%

    apache · http serverJul 20, 2014

  • crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

    MediumCVSS 5.5KEVWeaponizedEPSS 1%

    linux · linux kernelOct 13, 2025

  • OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after

    MediumCVSS 5.3WeaponizedEPSS 99%

    openbsd · opensshAug 17, 2018

  • Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-m

    CriticalCVSS 9.3WeaponizedEPSS 31%

    microsoft · windows 7Feb 10, 2010

  • Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote

    CriticalCVSS 9.3No exploitEPSS 26%

    microsoft · xml core servicesJan 8, 2007

  • Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML

    CriticalCVSS 9.3No exploitEPSS 24%

    microsoft · internet explorerMar 31, 2010

  • Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.

    CriticalCVSS 10.0Proof of conceptEPSS 13%

    qemu · qemuMar 24, 2017

  • Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (me

    CriticalCVSS 9.3No exploitEPSS 21%

    microsoft · internet explorerAug 11, 2010

  • A race condition was addressed with additional validation.

    HighCVSS 7.0WeaponizedEPSS 46%

    apple · safariDec 15, 2022

  • In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p

    HighCVSS 8.1WeaponizedEPSS 33%

    freebsd · freebsdJul 9, 2020

  • Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the

    CriticalCVSS 10.0No exploitEPSS 2%

    cisco · wireless lan controller softwareMar 6, 2014

  • Data race in crossbeam-deque

    CriticalCVSS 9.8No exploitEPSS 2%

    crossbeam project · crossbeamAug 2, 2021

  • Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."

    CriticalCVSS 10.0No exploitEPSS 1%

    sangoma · wanpipeApr 3, 2009

  • Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.

    CriticalCVSS 10.0No exploitEPSS 1%

    google · chromeApr 1, 2010

All vulnerability classes