CWE-362 · 2 464 записей
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE этого класса
2 467 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-36884Готовый эксплойт | Windows Search Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-362 | Высокая7,5 | KEV | 98,9 % | 11 июл. 2023 г. |
83Срочно | CVE-2016-5195Готовый эксплойт | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect halinux · linux kernel · CWE-362 | Высокая7,0 | KEV | 83,5 % | 10 нояб. 2016 г. |
72На этой неделе | CVE-2021-21166Готовый эксплойт | Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTMgoogle · chrome · CWE-362 | Высокая8,8 | KEV | 24,0 % | 9 мар. 2021 г. |
64На этой неделе | CVE-2020-6820Готовый эксплойт | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | Высокая8,1 | KEV | 7,1 % | 24 апр. 2020 г. |
63На этой неделе | CVE-2022-26904Готовый эксплойт | Windows User Profile Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-362 | Высокая7,0 | KEV | 16,9 % | 15 апр. 2022 г. |
63На этой неделе | CVE-2020-6819Готовый эксплойт | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | Высокая8,1 | KEV | 3,0 % | 24 апр. 2020 г. |
60На этой неделе | CVE-2025-62215Готовый эксплойт | Windows Kernel Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-362 | Высокая7,0 | KEV | 6,0 % | 11 нояб. 2025 г. |
59В плане | CVE-2014-0196Готовый эксплойт | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO linux · linux kernel · CWE-362 | Средняя5,5 | KEV | 22,5 % | 7 мая 2014 г. |
58В плане | CVE-2024-27983Proof of concept | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 fnodejs · node · CWE-362 | Высокая8,2 | — | 87,2 % | 8 апр. 2024 г. |
55В плане | CVE-2021-0920Готовый эксплойт | In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition.linux · linux kernel · CWE-362 | Средняя6,4 | KEV | 0,8 % | 15 дек. 2021 г. |
55В плане | CVE-2021-25395Готовый эксплойт | A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilsamsung · android · CWE-362 | Средняя6,4 | KEV | 0,4 % | 11 июн. 2021 г. |
53В плане | CVE-2014-0226Proof of concept | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-bapache · http server · CWE-362 | Средняя6,8 | — | 85,7 % | 20 июл. 2014 г. |
52В плане | CVE-2025-39964Готовый эксплойт | crypto: af_alg - Disallow concurrent writes in af_alg_sendmsglinux · linux kernel · CWE-362 | Средняя5,5 | KEV | 1,0 % | 13 окт. 2025 г. |
51В плане | CVE-2018-15473Готовый эксплойт | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after openbsd · openssh · CWE-362 | Средняя5,3 | — | 98,6 % | 17 авг. 2018 г. |
46В плане | CVE-2010-0017Готовый эксплойт | Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-mmicrosoft · windows 7 · CWE-362 | Критическая9,3 | — | 30,8 % | 10 февр. 2010 г. |
45В плане | CVE-2007-0099Эксплойта нет | Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remotemicrosoft · xml core services · CWE-362 | Критическая9,3 | — | 25,1 % | 8 янв. 2007 г. |
44В плане | CVE-2010-0489Эксплойта нет | Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTMLmicrosoft · internet explorer · CWE-362 | Критическая9,3 | — | 23,7 % | 31 мар. 2010 г. |
44В плане | CVE-2015-8556Proof of concept | Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.qemu · qemu · CWE-362 | Критическая10,0 | — | 13,4 % | 24 мар. 2017 г. |
43В плане | CVE-2010-2558Эксплойта нет | Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memicrosoft · internet explorer · CWE-362 | Критическая9,3 | — | 21,0 % | 11 авг. 2010 г. |
42В плане | CVE-2022-46689Готовый эксплойт | A race condition was addressed with additional validation.apple · safari · CWE-362 | Высокая7,0 | — | 46,1 % | 15 дек. 2022 г. |
42В плане | CVE-2020-7457Готовый эксплойт | In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before pfreebsd · freebsd · CWE-362 | Высокая8,1 | — | 33,1 % | 9 июл. 2020 г. |
41В плане | CVE-2014-0703Эксплойта нет | Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the cisco · wireless lan controller software · CWE-362 | Критическая10,0 | — | 2,0 % | 6 мар. 2014 г. |
40В плане | CVE-2021-32810Эксплойта нет | Data race in crossbeam-dequecrossbeam project · crossbeam · CWE-362 | Критическая9,8 | — | 1,9 % | 2 авг. 2021 г. |
40В плане | CVE-2008-6598Эксплойта нет | Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."sangoma · wanpipe · CWE-362 | Критическая10,0 | — | 1,1 % | 3 апр. 2009 г. |
40В плане | CVE-2010-1228Эксплойта нет | Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.google · chrome · CWE-362 | Критическая10,0 | — | 0,8 % | 1 апр. 2010 г. |
- CVE-2023-3688490Срочно
Windows Search Remote Code Execution Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 99 %microsoft · windows 10 150711 июл. 2023 г.
- CVE-2016-519583Срочно
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 84 %linux · linux kernel10 нояб. 2016 г.
- CVE-2021-2116672На этой неделе
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 24 %google · chrome9 мар. 2021 г.
- CVE-2020-682064На этой неделе
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 7 %mozilla · firefox24 апр. 2020 г.
- CVE-2022-2690463На этой неделе
Windows User Profile Service Elevation of Privilege Vulnerability
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 17 %microsoft · windows 10 150715 апр. 2022 г.
- CVE-2020-681963На этой неделе
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 3 %mozilla · firefox24 апр. 2020 г.
- CVE-2025-6221560На этой неделе
Windows Kernel Elevation of Privilege Vulnerability
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 6 %microsoft · windows 10 180911 нояб. 2025 г.
- CVE-2014-019659В плане
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 22 %linux · linux kernel7 мая 2014 г.
- CVE-2024-2798358В плане
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 f
ВысокаяCVSS 8,2Proof of conceptEPSS 87 %nodejs · node8 апр. 2024 г.
- CVE-2021-092055В плане
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition.
СредняяCVSS 6,4KEVГотовый эксплойтEPSS 1 %linux · linux kernel15 дек. 2021 г.
- CVE-2021-2539555В плане
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privil
СредняяCVSS 6,4KEVГотовый эксплойтEPSS 0 %samsung · android11 июн. 2021 г.
- CVE-2014-022653В плане
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-b
СредняяCVSS 6,8Proof of conceptEPSS 86 %apache · http server20 июл. 2014 г.
- CVE-2025-3996452В плане
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 1 %linux · linux kernel13 окт. 2025 г.
- CVE-2018-1547351В плане
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after
СредняяCVSS 5,3Готовый эксплойтEPSS 99 %openbsd · openssh17 авг. 2018 г.
- CVE-2010-001746В плане
Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-m
КритическаяCVSS 9,3Готовый эксплойтEPSS 31 %microsoft · windows 710 февр. 2010 г.
- CVE-2007-009945В плане
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote
КритическаяCVSS 9,3Эксплойта нетEPSS 25 %microsoft · xml core services8 янв. 2007 г.
- CVE-2010-048944В плане
Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML
КритическаяCVSS 9,3Эксплойта нетEPSS 24 %microsoft · internet explorer31 мар. 2010 г.
- CVE-2015-855644В плане
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
КритическаяCVSS 10,0Proof of conceptEPSS 13 %qemu · qemu24 мар. 2017 г.
- CVE-2010-255843В плане
Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (me
КритическаяCVSS 9,3Эксплойта нетEPSS 21 %microsoft · internet explorer11 авг. 2010 г.
- CVE-2022-4668942В плане
A race condition was addressed with additional validation.
ВысокаяCVSS 7,0Готовый эксплойтEPSS 46 %apple · safari15 дек. 2022 г.
- CVE-2020-745742В плане
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p
ВысокаяCVSS 8,1Готовый эксплойтEPSS 33 %freebsd · freebsd9 июл. 2020 г.
- CVE-2014-070341В плане
Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %cisco · wireless lan controller software6 мар. 2014 г.
- CVE-2021-3281040В плане
Data race in crossbeam-deque
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %crossbeam project · crossbeam2 авг. 2021 г.
- CVE-2008-659840В плане
Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %sangoma · wanpipe3 апр. 2009 г.
- CVE-2010-122840В плане
Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %google · chrome1 апр. 2010 г.