CWE-667 · 663 kayıt
Improper Locking
Bu sınıftaki CVE’ler
663 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2025-43510Silahlaştırılmış | A memory corruption issue was addressed with improved lock state checking.apple · ipados · CWE-667 | Yüksek7,8 | KEV | %0,4 | 12 Ara 2025 |
59Planlayın | CVE-2021-1782Silahlaştırılmış | A race condition was addressed with improved locking.apple · ipados · CWE-667 | Yüksek7,0 | KEV | %2,2 | 2 Nis 2021 |
52Planlayın | CVE-2019-10072İstismar yok | The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1apache · tomcat · CWE-667 | Yüksek7,5 | — | %73,0 | 21 Haz 2019 |
40Planlayın | CVE-2020-12658İstismar yok | gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c.gssproxy project · gssproxy · CWE-667 | Kritik9,8 | — | %1,8 | 30 Ara 2020 |
39İzleyin | CVE-2019-5886İstismar yok | An issue was discovered in ShopXO 1.2.0.shopxo · shopxo · CWE-667 | Kritik9,8 | — | %1,0 | 10 Oca 2019 |
39İzleyin | CVE-2026-53049İstismar yok | gfs2: add some missing log lockinglinux · linux kernel · CWE-667 | Kritik9,8 | — | %0,6 | 24 Haz 2026 |
39İzleyin | CVE-2026-64068İstismar yok | netfs: Fix missing locking around retry adding new subreqslinux · linux kernel · CWE-667 | Kritik9,8 | — | %0,5 | 19 Tem 2026 |
39İzleyin | CVE-2026-64067İstismar yok | netfs: Fix missing barriers when accessing stream->subrequests locklesslylinux · linux kernel · CWE-667 | Kritik9,8 | — | %0,4 | 19 Tem 2026 |
39İzleyin | CVE-2021-22530İstismar yok | Improper account management vulnerability in NetIQ Advance Authenticationmicrofocus · netiq advanced authentication · CWE-667 | Kritik9,9 | — | %0,2 | 28 Ağu 2024 |
35İzleyin | CVE-2002-1850Kavram kanıtı | mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumptiapache · http server · CWE-667 | Yüksek7,5 | — | %17,4 | 31 Ara 2002 |
35İzleyin | CVE-2020-15674İstismar yok | Mozilla developers reported memory safety bugs present in Firefox 80.mozilla · firefox · CWE-667 | Yüksek8,8 | — | %0,8 | 1 Eki 2020 |
35İzleyin | CVE-2026-53071İstismar yok | Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsplinux · linux kernel · CWE-667 | Yüksek8,8 | — | %0,4 | 24 Haz 2026 |
35İzleyin | CVE-2026-43215İstismar yok | cifs: Fix locking usage for tcon fieldslinux · linux kernel · CWE-667 | Yüksek8,8 | — | %0,4 | 6 May 2026 |
35İzleyin | CVE-2026-31629İstismar yok | nfc: llcp: add missing return after LLCP_CLOSED checkslinux · linux kernel · CWE-667 | Yüksek8,8 | — | %0,4 | 24 Nis 2026 |
35İzleyin | CVE-2026-53358İstismar yok | Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()linux · linux kernel · CWE-667 | Yüksek8,8 | — | %0,3 | 2 Tem 2026 |
35İzleyin | CVE-2026-53072İstismar yok | Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFERlinux · linux kernel · CWE-667 | Yüksek8,8 | — | %0,3 | 24 Haz 2026 |
34İzleyin | CVE-2009-2699İstismar yok | The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as usedapache · http server · CWE-667 | Yüksek7,5 | — | %14,2 | 13 Eki 2009 |
34İzleyin | CVE-2026-21914İstismar yok | Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crashjuniper · junos · CWE-667 | Yüksek8,7 | — | %0,3 | 15 Oca 2026 |
33İzleyin | CVE-2004-0174İstismar yok | Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to apache · http server · CWE-667 | Yüksek7,5 | — | %11,5 | 4 May 2004 |
33İzleyin | CVE-2009-4272İstismar yok | A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to causlinux · linux kernel · CWE-667 | Yüksek7,5 | — | %11,1 | 27 Oca 2010 |
32İzleyin | CVE-2024-58087İstismar yok | ksmbd: fix racy issue from session lookup and expirelinux · linux kernel · CWE-667 | Yüksek8,1 | — | %0,5 | 12 Mar 2025 |
32İzleyin | CVE-2025-58153İstismar yok | BIG-IP HSB vulnerabilityf5 · big-ip access policy manager · CWE-667 | Yüksek8,2 | — | %0,2 | 15 Eki 2025 |
31İzleyin | CVE-2020-24606İstismar yok | Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handlsquid-cache · squid · CWE-667 | Yüksek7,5 | — | %5,0 | 24 Ağu 2020 |
31İzleyin | CVE-2006-5158İstismar yok | The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (proclinux · linux kernel · CWE-667 | Yüksek7,5 | — | %3,7 | 5 Eki 2006 |
31İzleyin | CVE-2006-2275İstismar yok | Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a lksctp · stream control transmission protocol · CWE-667 | Yüksek7,5 | — | %3,6 | 9 May 2006 |
- CVE-2025-4351061Bu hafta
A memory corruption issue was addressed with improved lock state checking.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %0apple · ipados12 Ara 2025
- CVE-2021-178259Planlayın
A race condition was addressed with improved locking.
YüksekCVSS 7,0KEVSilahlaştırılmışEPSS %2apple · ipados2 Nis 2021
- CVE-2019-1007252Planlayın
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1
YüksekCVSS 7,5İstismar yokEPSS %73apache · tomcat21 Haz 2019
- CVE-2020-1265840Planlayın
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c.
KritikCVSS 9,8İstismar yokEPSS %2gssproxy project · gssproxy30 Ara 2020
- CVE-2019-588639İzleyin
An issue was discovered in ShopXO 1.2.0.
KritikCVSS 9,8İstismar yokEPSS %1shopxo · shopxo10 Oca 2019
- CVE-2026-5304939İzleyin
gfs2: add some missing log locking
KritikCVSS 9,8İstismar yokEPSS %1linux · linux kernel24 Haz 2026
- CVE-2026-6406839İzleyin
netfs: Fix missing locking around retry adding new subreqs
KritikCVSS 9,8İstismar yokEPSS %1linux · linux kernel19 Tem 2026
- CVE-2026-6406739İzleyin
netfs: Fix missing barriers when accessing stream->subrequests locklessly
KritikCVSS 9,8İstismar yokEPSS %0linux · linux kernel19 Tem 2026
- CVE-2021-2253039İzleyin
Improper account management vulnerability in NetIQ Advance Authentication
KritikCVSS 9,9İstismar yokEPSS %0microfocus · netiq advanced authentication28 Ağu 2024
- CVE-2002-185035İzleyin
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumpti
YüksekCVSS 7,5Kavram kanıtıEPSS %17apache · http server31 Ara 2002
- CVE-2020-1567435İzleyin
Mozilla developers reported memory safety bugs present in Firefox 80.
YüksekCVSS 8,8İstismar yokEPSS %1mozilla · firefox1 Eki 2020
- CVE-2026-5307135İzleyin
Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
YüksekCVSS 8,8İstismar yokEPSS %0linux · linux kernel24 Haz 2026
- CVE-2026-4321535İzleyin
cifs: Fix locking usage for tcon fields
YüksekCVSS 8,8İstismar yokEPSS %0linux · linux kernel6 May 2026
- CVE-2026-3162935İzleyin
nfc: llcp: add missing return after LLCP_CLOSED checks
YüksekCVSS 8,8İstismar yokEPSS %0linux · linux kernel24 Nis 2026
- CVE-2026-5335835İzleyin
Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
YüksekCVSS 8,8İstismar yokEPSS %0linux · linux kernel2 Tem 2026
- CVE-2026-5307235İzleyin
Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
YüksekCVSS 8,8İstismar yokEPSS %0linux · linux kernel24 Haz 2026
- CVE-2009-269934İzleyin
The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used
YüksekCVSS 7,5İstismar yokEPSS %14apache · http server13 Eki 2009
- CVE-2026-2191434İzleyin
Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
YüksekCVSS 8,7İstismar yokEPSS %0juniper · junos15 Oca 2026
- CVE-2004-017433İzleyin
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %12apache · http server4 May 2004
- CVE-2009-427233İzleyin
A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to caus
YüksekCVSS 7,5İstismar yokEPSS %11linux · linux kernel27 Oca 2010
- CVE-2024-5808732İzleyin
ksmbd: fix racy issue from session lookup and expire
YüksekCVSS 8,1İstismar yokEPSS %1linux · linux kernel12 Mar 2025
- CVE-2025-5815332İzleyin
BIG-IP HSB vulnerability
YüksekCVSS 8,2İstismar yokEPSS %0f5 · big-ip access policy manager15 Eki 2025
- CVE-2020-2460631İzleyin
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handl
YüksekCVSS 7,5İstismar yokEPSS %5squid-cache · squid24 Ağu 2020
- CVE-2006-515831İzleyin
The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (proc
YüksekCVSS 7,5İstismar yokEPSS %4linux · linux kernel5 Eki 2006
- CVE-2006-227531İzleyin
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a
YüksekCVSS 7,5İstismar yokEPSS %4lksctp · stream control transmission protocol9 May 2006