Skip to main content

CWE archive

CWE-362 CVEs

Programmatic archive

2,498 CVEs tagged with CWE-36259 Critical, 1,127 High, 1,195 Medium, 117 Low, 0 Unrated.

CVE-2015-3212

Published Aug 31, 2015

Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows local users to cause a denial of service (list corruption and panic) via a rapid series of system calls…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5754

Published Aug 17, 2015

Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged con…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-2418

Published Jul 20, 2015

Race condition in Microsoft Malicious Software Removal Tool (MSRT) before 5.26 allows local users to gain privileges via a crafted DLL, aka "MSRT Race Condition Vulnerability."

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3709

Published Jul 3, 2015

Race condition in kext tools in Apple OS X before 10.10.4 allows local users to bypass intended signature requirements for kernel extensions by leveraging improper pathname valida…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4199

Published Jun 27, 2015

Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of serv…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1791

Published Jun 12, 2015

Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b, when used…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-3339

Published May 27, 2015

Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9710

Published May 27, 2015

The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypas…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2715

Published May 14, 2015

Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2234

Published May 12, 2015

Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local us…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1882

Published Apr 27, 2015

Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conf…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2706

Published Apr 27, 2015

Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of ser…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1099

Published Apr 10, 2015

Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a den…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1420

Published Mar 16, 2015

Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operation…

CVSS 1.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0654

Published Mar 13, 2015

Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to caus…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0632

Published Feb 27, 2015

Race condition in the Neighbor Discovery (ND) protocol implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service via a flood of Router Solicitati…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0609

Published Feb 16, 2015

Race condition in the Common Classification Engine (CCE) in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows re…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0245

Published Feb 13, 2015

D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort
Showing 2,151-2,175 of 2,498 CVEsPage 87 of 100