CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 6 of 55
- CVE-2023-33170HIGHCVSS 8.1EG 8.12023-07-11
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
- CVE-2023-24903HIGHCVSS 8.1EG 8.12023-05-09
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2023-21712HIGHCVSS 8.1EG 8.12023-04-27
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-23404HIGHCVSS 8.1EG 8.12023-03-14
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-42951HIGHCVSS 8.1EG 8.12023-02-06
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authenticati…
- CVE-2021-36532HIGHCVSS 8.1EG 8.12023-02-03
Race condition vulnerability discovered in portfolioCMS 1.0 allows remote attackers to run arbitrary code via fileExt parameter to localhost/admin/uploads.php.
- CVE-2023-21679HIGHCVSS 8.1EG 8.12023-01-10
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- CVE-2023-21546HIGHCVSS 8.1EG 8.12023-01-10
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- CVE-2023-21535HIGHCVSS 8.1EG 8.12023-01-10
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2022-44676HIGHCVSS 8.1EG 8.12022-12-13
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2022-41088HIGHCVSS 8.1EG 8.12022-11-09
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-41044HIGHCVSS 8.1EG 8.12022-11-09
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-41039HIGHCVSS 8.1EG 8.12022-11-09
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-38047HIGHCVSS 8.1EG 8.12022-10-11
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-38000HIGHCVSS 8.1EG 8.12022-10-11
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-33634HIGHCVSS 8.1EG 8.12022-10-11
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-30198HIGHCVSS 8.1EG 8.12022-10-11
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-24504HIGHCVSS 8.1EG 8.12022-10-11
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-22035HIGHCVSS 8.1EG 8.12022-10-11
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-34702HIGHCVSS 8.1EG 8.12022-08-09
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2022-37035HIGHCVSS 8.1EG 8.12022-08-02
An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Inform…
- CVE-2022-24800HIGHCVSS 8.1EG 8.12022-07-12
October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own filename in the `fro…
- CVE-2022-25090HIGHCVSS 8.1EG 8.12022-03-10
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.
- CVE-2022-23639HIGHCVSS 8.1EG 8.12022-02-15
crossbeam-utils provides atomics, synchronization primitives, scoped threads, and other utilities for concurrent programming in Rust. crossbeam-utils prior to version 0.8.7 incorrectly assumed that the alignment of `{i,u}64` was always the…
- CVE-2021-37134HIGHCVSS 8.1EG 8.12022-01-03
Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.
- CVE-2021-45710HIGHCVSS 8.1EG 8.12021-12-27
An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.
- CVE-2021-45704HIGHCVSS 8.1EG 8.12021-12-27
An issue was discovered in the metrics-util crate before 0.7.0 for Rust. There is a data race and memory corruption because AtomicBucket<T> unconditionally implements the Send and Sync traits.
- CVE-2017-13905HIGHCVSS 8.1EG 8.12021-12-23
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be …
- CVE-2021-37074HIGHCVSS 8.1EG 8.12021-12-08
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.
- CVE-2021-0870HIGHCVSS 8.1EG 8.12021-10-22
In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.…
- CVE-2021-29986HIGHCVSS 8.1EG 8.12021-08-17
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects …
- CVE-2020-36463HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>.
- CVE-2020-36461HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock.
- CVE-2020-36460HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation of the Send and Sync traits without regard for the inner type.
- CVE-2020-36459HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore.
- CVE-2020-36458HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the lexer crate through 2020-11-10 for Rust. For ReaderResult<T, E>, there is an implementation of Sync with a trait bound of T: Send, E: Send.
- CVE-2020-36456HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds on the contained type.
- CVE-2020-36454HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the parc crate through 2020-11-14 for Rust. LockWeak<T> has an unconditional implementation of Send without trait bounds on T.
- CVE-2020-36453HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the scottqueue crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for Queue<T>.
- CVE-2020-36450HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch<T>.
- CVE-2020-36448HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>.
- CVE-2020-36447HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the v9 crate through 2020-12-18 for Rust. There is an unconditional implementation of Sync for SyncRef<T>.
- CVE-2020-36446HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the signal-simple crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for SyncChannel<T>.
- CVE-2020-36445HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the convec crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for ConVec<T>.
- CVE-2020-36444HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the async-coap crate through 2020-12-08 for Rust. Send and Sync are implemented for ArcGuard<RC, T> without trait bounds on RC.
- CVE-2020-36442HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the beef crate before 0.5.0 for Rust. beef::Cow has no Sync bound on its Send trait.
- CVE-2020-36441HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the abox crate before 0.4.1 for Rust. It implements Send and Sync for AtomicBox<T> with no requirement for T: Send and T: Sync.
- CVE-2020-36440HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the libsbc crate before 0.1.5 for Rust. For Decoder<R>, it implements Send for any R: Read.
- CVE-2020-36439HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the ticketed_lock crate before 0.3.0 for Rust. There are unconditional implementations of Send for ReadTicket<T> and WriteTicket<T>.
- CVE-2020-36438HIGHCVSS 8.1EG 8.12021-08-08
An issue was discovered in the tiny_future crate before 0.4.0 for Rust. Future<T> does not have bounds on its Send and Sync traits.
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →