Skip to content
Noroxi

CWE-667 · 669 records

Improper Locking

CVEs in this class

669 records

  • CVE-2025-43510
    61This week

    A memory corruption issue was addressed with improved lock state checking.

    HighCVSS 7.8KEVWeaponizedEPSS 0%

    apple · ipadosDec 12, 2025

  • A race condition was addressed with improved locking.

    HighCVSS 7.0KEVWeaponizedEPSS 2%

    apple · ipadosApr 2, 2021

  • The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1

    HighCVSS 7.5No exploitEPSS 73%

    apache · tomcatJun 21, 2019

  • gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c.

    CriticalCVSS 9.8No exploitEPSS 2%

    gssproxy project · gssproxyDec 30, 2020

  • CVE-2019-5886
    39Monitor

    An issue was discovered in ShopXO 1.2.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    shopxo · shopxoJan 10, 2019

  • netfs: Fix missing locking around retry adding new subreqs

    CriticalCVSS 9.8No exploitEPSS 1%

    linux · linux kernelJul 19, 2026

  • netfs: Fix missing barriers when accessing stream->subrequests locklessly

    CriticalCVSS 9.8No exploitEPSS 0%

    linux · linux kernelJul 19, 2026

  • gfs2: add some missing log locking

    CriticalCVSS 9.8No exploitEPSS 0%

    linux · linux kernelJun 24, 2026

  • Improper account management vulnerability in NetIQ Advance Authentication

    CriticalCVSS 9.9No exploitEPSS 0%

    microfocus · netiq advanced authenticationAug 28, 2024

  • CVE-2002-1850
    35Monitor

    mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumpti

    HighCVSS 7.5Proof of conceptEPSS 17%

    apache · http serverDec 31, 2002

  • Mozilla developers reported memory safety bugs present in Firefox 80.

    HighCVSS 8.8No exploitEPSS 1%

    mozilla · firefoxOct 1, 2020

  • Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp

    HighCVSS 8.8No exploitEPSS 0%

    linux · linux kernelJun 24, 2026

  • cifs: Fix locking usage for tcon fields

    HighCVSS 8.8No exploitEPSS 0%

    linux · linux kernelMay 6, 2026

  • nfc: llcp: add missing return after LLCP_CLOSED checks

    HighCVSS 8.8No exploitEPSS 0%

    linux · linux kernelApr 24, 2026

  • Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()

    HighCVSS 8.8No exploitEPSS 0%

    linux · linux kernelJul 2, 2026

  • Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER

    HighCVSS 8.8No exploitEPSS 0%

    linux · linux kernelJun 24, 2026

  • CVE-2009-2699
    34Monitor

    The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used

    HighCVSS 7.5No exploitEPSS 14%

    apache · http serverOct 13, 2009

  • Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash

    HighCVSS 8.7No exploitEPSS 0%

    juniper · junosJan 15, 2026

  • CVE-2004-0174
    33Monitor

    Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to

    HighCVSS 7.5No exploitEPSS 12%

    apache · http serverMay 4, 2004

  • CVE-2009-4272
    33Monitor

    A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to caus

    HighCVSS 7.5No exploitEPSS 11%

    linux · linux kernelJan 27, 2010

  • ksmbd: fix racy issue from session lookup and expire

    HighCVSS 8.1No exploitEPSS 1%

    linux · linux kernelMar 12, 2025

  • BIG-IP HSB vulnerability

    HighCVSS 8.2No exploitEPSS 0%

    f5 · big-ip access policy managerOct 15, 2025

  • Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handl

    HighCVSS 7.5No exploitEPSS 5%

    squid-cache · squidAug 24, 2020

  • CVE-2006-5158
    31Monitor

    The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (proc

    HighCVSS 7.5No exploitEPSS 4%

    linux · linux kernelOct 5, 2006

  • CVE-2006-2275
    31Monitor

    Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a

    HighCVSS 7.5No exploitEPSS 4%

    lksctp · stream control transmission protocolMay 9, 2006

All vulnerability classes