Skip to main content

CWE archive

CWE-362 CVEs

Programmatic archive

2,498 CVEs tagged with CWE-36259 Critical, 1,127 High, 1,195 Medium, 117 Low, 0 Unrated.

CVE-2016-0848

Published Apr 18, 2016

Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-a…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1267

Published Apr 15, 2016

Race condition in the RPC functionality in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1757

Published Mar 24, 2016

Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS 7.0 · High
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2016-1975

Published Mar 13, 2016

Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0723

Published Feb 8, 2016

Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7550

Published Feb 8, 2016

The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel before 4.3.4 does not properly use a semaphore, which allows local users to cause a denial of service (N…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0858

Published Jan 15, 2016

Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted request.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8511

Published Jan 9, 2016

Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7990

Published Dec 28, 2015

Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and syst…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8461

Published Dec 16, 2015

Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-6789

Published Dec 14, 2015

Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to cause a denial of service (use-after-free)…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-6126

Published Dec 9, 2015

Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windo…

CVSS 7.2 · High

CVE-2015-3196

Published Dec 6, 2015

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect dat…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2015-7189

Published Nov 5, 2015

Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of s…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7814

Published Oct 30, 2015

Race condition in the relinquish_memory function in arch/arm/domain.c in Xen 4.6.x and earlier allows local domains with partial management control to cause a denial of service (h…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-5240

Published Oct 27, 2015

Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to byp…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-7613

Published Oct 19, 2015

Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid c…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6761

Published Oct 15, 2015

The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome before 46.0.2490.71 and other products, relies on a coefficient-partition coun…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-4510

Published Sep 24, 2015

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-aft…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 2,126-2,150 of 2,498 CVEsPage 86 of 100