CWE-667 · 669 records
Improper Locking
CVEs in this class
669 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2025-43510Weaponized | A memory corruption issue was addressed with improved lock state checking.apple · ipados · CWE-667 | High7.8 | KEV | 0.4% | Dec 12, 2025 |
59Plan | CVE-2021-1782Weaponized | A race condition was addressed with improved locking.apple · ipados · CWE-667 | High7.0 | KEV | 2.2% | Apr 2, 2021 |
52Plan | CVE-2019-10072No exploit | The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1apache · tomcat · CWE-667 | High7.5 | — | 73.0% | Jun 21, 2019 |
40Plan | CVE-2020-12658No exploit | gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c.gssproxy project · gssproxy · CWE-667 | Critical9.8 | — | 1.8% | Dec 30, 2020 |
39Monitor | CVE-2019-5886No exploit | An issue was discovered in ShopXO 1.2.0.shopxo · shopxo · CWE-667 | Critical9.8 | — | 1.0% | Jan 10, 2019 |
39Monitor | CVE-2026-64068No exploit | netfs: Fix missing locking around retry adding new subreqslinux · linux kernel · CWE-667 | Critical9.8 | — | 0.5% | Jul 19, 2026 |
39Monitor | CVE-2026-64067No exploit | netfs: Fix missing barriers when accessing stream->subrequests locklesslylinux · linux kernel · CWE-667 | Critical9.8 | — | 0.4% | Jul 19, 2026 |
39Monitor | CVE-2026-53049No exploit | gfs2: add some missing log lockinglinux · linux kernel · CWE-667 | Critical9.8 | — | 0.4% | Jun 24, 2026 |
39Monitor | CVE-2021-22530No exploit | Improper account management vulnerability in NetIQ Advance Authenticationmicrofocus · netiq advanced authentication · CWE-667 | Critical9.9 | — | 0.2% | Aug 28, 2024 |
35Monitor | CVE-2002-1850Proof of concept | mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumptiapache · http server · CWE-667 | High7.5 | — | 17.4% | Dec 31, 2002 |
35Monitor | CVE-2020-15674No exploit | Mozilla developers reported memory safety bugs present in Firefox 80.mozilla · firefox · CWE-667 | High8.8 | — | 0.8% | Oct 1, 2020 |
35Monitor | CVE-2026-53071No exploit | Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsplinux · linux kernel · CWE-667 | High8.8 | — | 0.4% | Jun 24, 2026 |
35Monitor | CVE-2026-43215No exploit | cifs: Fix locking usage for tcon fieldslinux · linux kernel · CWE-667 | High8.8 | — | 0.4% | May 6, 2026 |
35Monitor | CVE-2026-31629No exploit | nfc: llcp: add missing return after LLCP_CLOSED checkslinux · linux kernel · CWE-667 | High8.8 | — | 0.4% | Apr 24, 2026 |
35Monitor | CVE-2026-53358No exploit | Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()linux · linux kernel · CWE-667 | High8.8 | — | 0.3% | Jul 2, 2026 |
35Monitor | CVE-2026-53072No exploit | Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFERlinux · linux kernel · CWE-667 | High8.8 | — | 0.2% | Jun 24, 2026 |
34Monitor | CVE-2009-2699No exploit | The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as usedapache · http server · CWE-667 | High7.5 | — | 14.2% | Oct 13, 2009 |
34Monitor | CVE-2026-21914No exploit | Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crashjuniper · junos · CWE-667 | High8.7 | — | 0.3% | Jan 15, 2026 |
33Monitor | CVE-2004-0174No exploit | Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to apache · http server · CWE-667 | High7.5 | — | 11.5% | May 4, 2004 |
33Monitor | CVE-2009-4272No exploit | A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to causlinux · linux kernel · CWE-667 | High7.5 | — | 11.1% | Jan 27, 2010 |
32Monitor | CVE-2024-58087No exploit | ksmbd: fix racy issue from session lookup and expirelinux · linux kernel · CWE-667 | High8.1 | — | 0.5% | Mar 12, 2025 |
32Monitor | CVE-2025-58153No exploit | BIG-IP HSB vulnerabilityf5 · big-ip access policy manager · CWE-667 | High8.2 | — | 0.2% | Oct 15, 2025 |
31Monitor | CVE-2020-24606No exploit | Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handlsquid-cache · squid · CWE-667 | High7.5 | — | 5.0% | Aug 24, 2020 |
31Monitor | CVE-2006-5158No exploit | The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (proclinux · linux kernel · CWE-667 | High7.5 | — | 3.7% | Oct 5, 2006 |
31Monitor | CVE-2006-2275No exploit | Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a lksctp · stream control transmission protocol · CWE-667 | High7.5 | — | 3.6% | May 9, 2006 |
- CVE-2025-4351061This week
A memory corruption issue was addressed with improved lock state checking.
HighCVSS 7.8KEVWeaponizedEPSS 0%apple · ipadosDec 12, 2025
- CVE-2021-178259Plan
A race condition was addressed with improved locking.
HighCVSS 7.0KEVWeaponizedEPSS 2%apple · ipadosApr 2, 2021
- CVE-2019-1007252Plan
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1
HighCVSS 7.5No exploitEPSS 73%apache · tomcatJun 21, 2019
- CVE-2020-1265840Plan
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c.
CriticalCVSS 9.8No exploitEPSS 2%gssproxy project · gssproxyDec 30, 2020
- CVE-2019-588639Monitor
An issue was discovered in ShopXO 1.2.0.
CriticalCVSS 9.8No exploitEPSS 1%shopxo · shopxoJan 10, 2019
- CVE-2026-6406839Monitor
netfs: Fix missing locking around retry adding new subreqs
CriticalCVSS 9.8No exploitEPSS 1%linux · linux kernelJul 19, 2026
- CVE-2026-6406739Monitor
netfs: Fix missing barriers when accessing stream->subrequests locklessly
CriticalCVSS 9.8No exploitEPSS 0%linux · linux kernelJul 19, 2026
- CVE-2026-5304939Monitor
gfs2: add some missing log locking
CriticalCVSS 9.8No exploitEPSS 0%linux · linux kernelJun 24, 2026
- CVE-2021-2253039Monitor
Improper account management vulnerability in NetIQ Advance Authentication
CriticalCVSS 9.9No exploitEPSS 0%microfocus · netiq advanced authenticationAug 28, 2024
- CVE-2002-185035Monitor
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumpti
HighCVSS 7.5Proof of conceptEPSS 17%apache · http serverDec 31, 2002
- CVE-2020-1567435Monitor
Mozilla developers reported memory safety bugs present in Firefox 80.
HighCVSS 8.8No exploitEPSS 1%mozilla · firefoxOct 1, 2020
- CVE-2026-5307135Monitor
Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
HighCVSS 8.8No exploitEPSS 0%linux · linux kernelJun 24, 2026
- CVE-2026-4321535Monitor
cifs: Fix locking usage for tcon fields
HighCVSS 8.8No exploitEPSS 0%linux · linux kernelMay 6, 2026
- CVE-2026-3162935Monitor
nfc: llcp: add missing return after LLCP_CLOSED checks
HighCVSS 8.8No exploitEPSS 0%linux · linux kernelApr 24, 2026
- CVE-2026-5335835Monitor
Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
HighCVSS 8.8No exploitEPSS 0%linux · linux kernelJul 2, 2026
- CVE-2026-5307235Monitor
Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
HighCVSS 8.8No exploitEPSS 0%linux · linux kernelJun 24, 2026
- CVE-2009-269934Monitor
The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used
HighCVSS 7.5No exploitEPSS 14%apache · http serverOct 13, 2009
- CVE-2026-2191434Monitor
Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
HighCVSS 8.7No exploitEPSS 0%juniper · junosJan 15, 2026
- CVE-2004-017433Monitor
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to
HighCVSS 7.5No exploitEPSS 12%apache · http serverMay 4, 2004
- CVE-2009-427233Monitor
A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to caus
HighCVSS 7.5No exploitEPSS 11%linux · linux kernelJan 27, 2010
- CVE-2024-5808732Monitor
ksmbd: fix racy issue from session lookup and expire
HighCVSS 8.1No exploitEPSS 1%linux · linux kernelMar 12, 2025
- CVE-2025-5815332Monitor
BIG-IP HSB vulnerability
HighCVSS 8.2No exploitEPSS 0%f5 · big-ip access policy managerOct 15, 2025
- CVE-2020-2460631Monitor
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handl
HighCVSS 7.5No exploitEPSS 5%squid-cache · squidAug 24, 2020
- CVE-2006-515831Monitor
The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (proc
HighCVSS 7.5No exploitEPSS 4%linux · linux kernelOct 5, 2006
- CVE-2006-227531Monitor
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a
HighCVSS 7.5No exploitEPSS 4%lksctp · stream control transmission protocolMay 9, 2006