Skip to main content

CWE archive

CWE-362 CVEs

Programmatic archive

2,500 CVEs tagged with CWE-36259 Critical, 1,127 High, 1,197 Medium, 117 Low, 0 Unrated.

CVE-2017-7372

Published Jun 13, 2017

In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7368

Published Jun 13, 2017

In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2015-9022

Published Jun 13, 2017

In all Android releases from CAF using the Linux kernel, time-of-check Time-of-use (TOCTOU) Race Conditions exist in several TZ APIs.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9966

Published Jun 13, 2017

In all Android releases from CAF using the Linux kernel, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists in Secure Display.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10297

Published Jun 6, 2017

In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9941

Published Jun 6, 2017

In the Embedded File System in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000367

Published Jun 5, 2017

Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and…

CVSS 6.4 · Medium
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2017-2533

Published May 22, 2017

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitration" component. A race condition allows attackers to execu…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10242

Published May 16, 2017

A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases from CAF using the Linux kernel.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8997

Published May 16, 2017

In TrustZone a time-of-check time-of-use race condition could potentially exist in a listener routine in all Android releases from CAF using the Linux kernel.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8996

Published May 16, 2017

In TrustZone a time-of-check time-of-use race condition could potentially exist in a QFPROM routine in all Android releases from CAF using the Linux kernel.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9936

Published May 16, 2017

In TrustZone a time-of-check time-of-use race condition could potentially exist in an authentication routine in all Android releases from CAF using the Linux kernel.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8244

Published May 12, 2017

In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_buf->curr" and "dbg_buf->filled_size" could be modified by d…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0343

Published May 9, 2017

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) where user can trigger a race condition due to lack of synchr…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9256

Published May 9, 2017

In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the…

CVSS 7.5 · High

CVE-2017-8342

Published Apr 30, 2017

Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6615

Published Apr 20, 2017

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) co…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3106

Published Apr 13, 2017

Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0462

Published Apr 7, 2017

An elevation of privilege vulnerability in the Qualcomm Seemp driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This is…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7572

Published Apr 6, 2017

The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is sub…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 2,051-2,075 of 2,500 CVEsPage 83 of 100