CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 17 of 55
- CVE-2023-23407HIGHCVSS 7.1EG 7.12023-03-14
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
- CVE-2022-42930HIGHCVSS 7.1EG 7.12022-12-22
If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106.
- CVE-2022-3566HIGHCVSS 7.1EG 7.12022-10-17
A vulnerability was identified in Linux Kernel up to 4.19.316/5.4.278/5.10.220/5.15.161. This impacts the function tcp_getsockopt/tcp_setsockopt of the component TCP Handler. Such manipulation leads to race condition. A high complexity lev…
- CVE-2021-3752HIGHCVSS 7.1EG 7.12022-02-16
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their pr…
- CVE-2017-18018HIGHCVSS 7.1EG 7.12018-01-04
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leve…
- CVE-2025-66327HIGHCVSS 4.7EG 7.12025-12-08
Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-29211HIGHCVSS 4.7EG 7.12024-11-13
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
- CVE-2022-3567HIGHCVSS 4.6EG 7.12022-10-17
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function inet6_stream_ops/inet6_dgram_ops of the component IPv6 Handler. The manipulation leads to race condition. It is recommend…
- CVE-2015-0654HIGHCVSS v2 7.1EG 7.12015-03-13
Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HT…
- CVE-2015-0631HIGHCVSS v2 7.1EG 7.12015-02-21
Race condition in the SSL implementation on Cisco Intrusion Prevention System (IPS) devices allows remote attackers to cause a denial of service by making many management-interface HTTPS connections during the key-regeneration phase of an …
- CVE-2015-0609HIGHCVSS v2 7.1EG 7.12015-02-16
Race condition in the Common Classification Engine (CCE) in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) …
- CVE-2015-0608HIGHCVSS v2 7.1EG 7.12015-02-12
Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers …
- CVE-2014-3406HIGHCVSS v2 7.1EG 7.12014-10-19
Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, …
- CVE-2014-2706HIGHCVSS v2 7.1EG 7.12014-04-14
Race condition in the mac80211 subsystem in the Linux kernel before 3.13.7 allows remote attackers to cause a denial of service (system crash) via network traffic that improperly interacts with the WLAN_STA_PS_STA state (aka power-save mod…
- CVE-2014-2672HIGHCVSS v2 7.1EG 7.12014-04-01
Race condition in the ath_tx_aggr_sleep function in drivers/net/wireless/ath/ath9k/xmit.c in the Linux kernel before 3.13.7 allows remote attackers to cause a denial of service (system crash) via a large amount of network traffic that trig…
- CVE-2014-0710HIGHCVSS v2 7.1EG 7.12014-02-22
Race condition in the cut-through proxy feature in Cisco Firewall Services Module (FWSM) Software 3.x before 3.2(28) and 4.x before 4.1(15) allows remote attackers to cause a denial of service (device reload) via certain matching traffic, …
- CVE-2014-0616HIGHCVSS v2 7.1EG 7.12014-01-15
Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 before 12.1X46-D10, 12.2 before 12.2R7, 12.3 before 12.3R4-S2, 13.1 before 13.1R3-S1, 13.2 befo…
- CVE-2013-5512HIGHCVSS v2 7.1EG 7.12013-10-13
Race condition in the HTTP Deep Packet Inspection (DPI) feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.5), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.…
- CVE-2011-4348HIGHCVSS v2 7.1EG 7.12013-06-08
Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an…
- CVE-2012-3063HIGHCVSS v2 7.1EG 7.12012-06-20
Cisco Application Control Engine (ACE) before A4(2.3) and A5 before A5(1.1), when multicontext mode is enabled, does not properly share a management IP address among multiple contexts, which allows remote authenticated administrators to by…
- CVE-2012-1324HIGHCVSS v2 7.1EG 7.12012-05-03
Race condition in the Zone-Based Firewall in Cisco IOS 15.1 and 15.2, when IPS policies are configured, allows remote attackers to cause a denial of service (device crash) by sending IPv6 packets, aka Bug ID CSCtk53534.
- CVE-2010-4526HIGHCVSS v2 7.1EG 7.12011-01-11
Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is alrea…
- CVE-2009-4226HIGHCVSS v2 7.1EG 7.12009-12-08
Race condition in the IP module in the kernel in Sun OpenSolaris snv_106 through snv_124 allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors related to the (1) tcp_do_getsocknam…
- CVE-2009-4027HIGHCVSS v2 7.1EG 7.12009-12-02
Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block ACK (aka DELBA) packet that triggers a certain state change…
- CVE-2007-3091HIGHCVSS v2 7.1EG 7.12007-06-06
Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform ot…
- CVE-2026-56906HIGHCVSS 7.0EG 7.02026-10-06
In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-105773HIGHCVSS 7.0EG 7.02026-10-05
Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race condition and insufficient file validation, allowing a local attacker to execute arbitrary cod…
- CVE-2026-58880HIGHCVSS 7.0EG 7.02026-10-05
In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2026-98163HIGHCVSS 7.0EG 7.02026-09-26
In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup_task_release() to cgroup_task_free()") …
- CVE-2026-58734HIGHCVSS 7.0EG 7.02026-09-15
In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f…
- CVE-2026-58728HIGHCVSS 7.0EG 7.02026-09-15
In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-58724HIGHCVSS 7.0EG 7.02026-09-15
In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-58701HIGHCVSS 7.0EG 7.02026-09-15
In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi…
- CVE-2026-58848HIGHCVSS 7.0EG 7.02026-09-08
In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f…
- CVE-2026-73005HIGHCVSS 7.0EG 7.02026-09-08
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- CVE-2026-69441HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-69682HIGHCVSS 7.0EG 7.02026-09-08
Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69581HIGHCVSS 7.0EG 7.02026-09-08
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69398HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69385HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
- CVE-2026-69319HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-68840HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-77894HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-69448HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69404HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
- CVE-2026-68824HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
- CVE-2026-50349HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-58093HIGHCVSS 7.0EG 7.02026-08-26
The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently…
- CVE-2026-62727HIGHCVSS 7.0EG 7.02026-08-19
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-0295HIGHCVSS 7.0EG 7.02026-08-13
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →