CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 2 of 55
- CVE-2024-10468CRITICALCVSS 5.3EG 9.82024-10-29
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.
- CVE-2026-17855CRITICALCVSS 9.6EG 9.62026-07-30
Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-17711CRITICALCVSS 9.6EG 9.62026-07-30
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-17709CRITICALCVSS 9.6EG 9.62026-07-30
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-13882CRITICALCVSS 9.6EG 9.62026-06-30
Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2014-0100HIGHCVSS v2 9.3EG 9.32014-03-11
Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a larg…
- CVE-2014-1490HIGHCVSS v2 9.3EG 9.32014-02-06
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote atta…
- CVE-2013-7283HIGHCVSS v2 9.3EG 9.32014-01-09
Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact and attack vectors, involving the /var/tmp/libreswan-nss-pwd temporary file.
- CVE-2012-5108HIGHCVSS v2 9.3EG 9.32012-10-09
Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary code via vectors related to audio devices.
- CVE-2011-3961HIGHCVSS v2 9.3EG 9.32012-02-09
Race condition in Google Chrome before 17.0.963.46 allows remote attackers to execute arbitrary code via vectors that trigger a crash of a utility process.
- CVE-2010-3412HIGHCVSS v2 9.3EG 9.32010-09-16
Race condition in the console implementation in Google Chrome before 6.0.472.59 has unspecified impact and attack vectors.
- CVE-2010-2558HIGHCVSS v2 9.3EG 9.32010-08-11
Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption …
- CVE-2010-0489HIGHCVSS v2 9.3EG 9.32010-03-31
Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption Vulnerability."
- CVE-2010-0017HIGHCVSS v2 9.3EG 9.32010-02-10
Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Go…
- CVE-2009-2724HIGHCVSS v2 9.3EG 9.32009-08-10
Race condition in the java.lang package in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, related to a "3Y Race condition in reflection checks."
- CVE-2008-5021HIGHCVSS v2 9.3EG 9.32008-11-13
nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by m…
- CVE-2007-0099HIGHCVSS v2 9.3EG 9.32007-01-08
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nest…
- CVE-2025-13036CRITICALCVSS 9.2EG 9.22026-06-16
An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
- CVE-2026-92050CRITICALCVSS 9.1EG 9.12026-09-15
Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- CVE-2025-10263CRITICALCVSS 9.1EG 9.12026-06-09
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow…
- CVE-2025-1127CRITICALCVSS 9.1EG 9.12025-02-13
The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the filesystem.
- CVE-2026-77638CRITICALCVSS 9.0EG 9.02026-08-20
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
- CVE-2025-32991CRITICALCVSS 9.0EG 9.02026-03-25
In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.
- CVE-2026-20677CRITICALCVSS 9.0EG 9.02026-02-11
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut …
- CVE-2023-32250CRITICALCVSS 9.0EG 9.02023-07-10
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operati…
- CVE-2017-10915CRITICALCVSS 9.0EG 9.02017-07-05
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
- CVE-2024-27983CRITICALCVSS 8.2EG 9.02024-04-09
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTT…
- CVE-2024-6387CRITICALCVSS 8.1EG 9.02024-07-01
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by fai…
- CVE-2018-15473CRITICALCVSS 5.3EG 9.02018-08-17
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c,…
- CVE-2026-106201HIGHCVSS 8.8EG 8.82026-10-06
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106255HIGHCVSS 8.8EG 8.82026-10-06
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-104714HIGHCVSS 8.8EG 8.82026-10-05
Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the applicati…
- CVE-2026-98115HIGHCVSS 8.8EG 8.82026-09-25
In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions during logoff SMB3 multichannel allows requests for one session to run on multiple connections. Wait for all channels bound to a session bef…
- CVE-2026-55318HIGHCVSS 8.8EG 8.82026-09-15
In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-17712HIGHCVSS 8.8EG 8.82026-07-30
Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-50385HIGHCVSS 8.8EG 8.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
- CVE-2026-50369HIGHCVSS 8.8EG 8.82026-07-14
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50414HIGHCVSS 8.8EG 8.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
- CVE-2026-54999HIGHCVSS 8.8EG 8.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-54107HIGHCVSS 8.8EG 8.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2026-44693HIGHCVSS 8.8EG 8.82026-06-10
Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 r…
- CVE-2026-45945HIGHCVSS 8.8EG 8.82026-05-27
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix race condition during PASID entry replacement The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing an active PASID entry (e.g., during…
- CVE-2026-26167HIGHCVSS 8.8EG 8.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- CVE-2025-12432HIGHCVSS 8.8EG 8.82025-11-10
Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-8880HIGHCVSS 8.8EG 8.82025-08-13
Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-25214HIGHCVSS 8.8EG 8.82025-07-24
A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series of specially crafted HTTP request can lead to arbitrary code execution.
- CVE-2022-2742HIGHCVSS 8.8EG 8.82023-01-02
Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interact…
- CVE-2022-22763HIGHCVSS 8.8EG 8.82022-12-22
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.
- CVE-2022-28768HIGHCVSS 8.8EG 8.82022-11-17
The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process…
- CVE-2022-3307HIGHCVSS 8.8EG 8.82022-11-01
Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →