Skip to main content

CWE archive

CWE-362 CVEs

Programmatic archive

2,500 CVEs tagged with CWE-36259 Critical, 1,127 High, 1,197 Medium, 117 Low, 0 Unrated.

CVE-2015-0572

Published Oct 10, 2016

Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) A…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7777

Published Oct 7, 2016

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7098

Published Sep 26, 2016

Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0930

Published Sep 18, 2016

Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote atta…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6516

Published Aug 6, 2016

Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) o…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6480

Published Aug 6, 2016

Race condition in the ioctl_send_fib function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (out-of-bounds acc…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6156

Published Aug 6, 2016

Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6136

Published Aug 6, 2016

Race condition in the audit_log_single_execve_arg function in kernel/auditsc.c in the Linux kernel through 4.7 allows local users to bypass intended character-set restrictions or…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3760

Published Jul 11, 2016

Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairing that remains present during…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3744

Published Jul 11, 2016

Buffer overflow in the create_pbuf function in btif/src/btif_hh.c in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4955

Published Jul 5, 2016

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoo…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-4954

Published Jul 5, 2016

The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed p…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-6130

Published Jul 3, 2016

Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel me…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4309

Published Jun 30, 2016

Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8878

Published May 22, 2016

main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race conditi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8839

Published May 2, 2016

Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4170

Published May 2, 2016

Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_do…

CVSS 4.7 · Medium

CVE-2016-2812

Published Apr 30, 2016

Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitr…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-2547

Published Apr 27, 2016

sound/core/timer.c in the Linux kernel before 4.4.1 employs a locking approach that does not consider slave timer instances, which allows local users to cause a denial of service…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2546

Published Apr 27, 2016

sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and sys…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,101-2,125 of 2,500 CVEsPage 85 of 100