CWE-662— Improper Synchronization
The product utilizes multiple threads, processes, components, or systems to allow temporary access to a shared resource that can only be exclusive to one process at a time, but it does not properly synchronize these actions, which might cause simultaneous accesses of this resource by multiple threads or processes.— MITRE CWE catalog
69 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-662page 1 of 2
- CVE-2023-28229CRITICALCVSS 7.0EG 9.0⚠ KEV2023-04-11
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- CVE-2018-15555CRITICALCVSS 9.8EG 9.82019-06-28
On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the enabled onboard UART headers.
- CVE-2024-32644CRITICALCVSS 9.1EG 9.12024-04-19
Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ethereum. Prior to 17.0.0, there is a way to mint arbitrary tokens due to the possibility to have two different states not i…
- CVE-2026-53277HIGHCVSS 8.8EG 8.82026-06-25
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation walk_s1() and kvm_walk_nested_s2() expect to be called while holding kvm->srcu to…
- CVE-2022-23005HIGHCVSS 8.7EG 8.72023-01-23
Western Digital has identified a weakness in the UFS standard that could result in a security vulnerability. This vulnerability may exist in some systems where the Host boot ROM code implements the UFS Boot feature to boot from UFS complia…
- CVE-2016-8368HIGHCVSS 8.6EG 8.62017-02-13
An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions. The affected Ethernet interface module is connected to …
- CVE-2020-7457HIGHCVSS 8.1EG 8.22020-07-09
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race c…
- CVE-2022-1931HIGHCVSS 8.1EG 8.12022-05-31
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.
- CVE-2022-3565HIGHCVSS 4.6EG 8.02022-10-17
A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Bluetooth. The manipulation leads to use after…
- CVE-2022-2962HIGHCVSS 7.8EG 7.82022-09-13
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address is its own MMIO address. This can cause …
- CVE-2020-36208HIGHCVSS 7.8EG 7.82021-01-26
An issue was discovered in the conquer-once crate before 0.3.2 for Rust. Thread crossing can occur for a non-Send but Sync type, leading to memory corruption.
- CVE-2019-5675HIGHCVSS 7.8EG 7.82019-05-10
NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the product does not properly synchronize shared data, such as static va…
- CVE-2026-28789HIGHCVSS 7.5EG 7.52026-03-05
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2 login flow. Concurrent requests to /oauth/login can trigg…
- CVE-2025-27104HIGHCVSS 7.5EG 7.52025-02-21
vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a for loop. While the iterator expression cannot produce multiple writes, it can consume side effects…
- CVE-2024-7409HIGHCVSS 7.5EG 7.52024-08-05
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
- CVE-2023-2801HIGHCVSS 7.5EG 7.52023-06-06
Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The on…
- CVE-2021-20592HIGHCVSS 7.5EG 7.52021-08-05
Missing synchronization vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.39.010, GT25 model communication driver versions 01.19.000 through 01.39.010 and GT23 model communication driver versions…
- CVE-2020-36215HIGHCVSS 7.5EG 7.52021-01-26
An issue was discovered in the hashconsing crate before 1.1.0 for Rust. Because HConsed does not have bounds on its Send trait or Sync trait, memory corruption can occur.
- CVE-2020-14098HIGHCVSS 7.5EG 7.52021-01-13
The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
- CVE-2020-13759HIGHCVSS 7.5EG 7.52020-06-02
rust-vmm vm-memory before 0.1.1 and 0.2.x before 0.2.1 allows attackers to cause a denial of service (loss of IP networking) because read_obj and write_obj do not properly access memory. This affects aarch64 (with musl or glibc) and x86_64…
- CVE-2019-17185HIGHCVSS 7.5EG 7.52020-03-21
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handsh…
- CVE-2019-16137HIGHCVSS 7.5EG 7.52019-09-09
An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclusion.
- CVE-2018-4027HIGHCVSS 7.5EG 7.52019-05-13
An exploitable denial-of-service vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a semaphore deadloc…
- CVE-2019-19577HIGHCVSS 7.2EG 7.22019-12-11
An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. When running on AMD systems wit…
- CVE-2023-5088HIGHCVSS 7.0EG 7.02023-11-03
A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual d…
- CVE-2020-25668HIGHCVSS 7.0EG 7.02021-05-26
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
- CVE-2020-36211HIGHCVSS 7.0EG 7.02021-01-26
An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send trait or Sync trait, a data race and memory corruption can occur.
- CVE-2020-36207HIGHCVSS 7.0EG 7.02021-01-26
An issue was discovered in the aovec crate through 2020-12-10 for Rust. Because Aovec<T> does not have bounds on its Send trait or Sync trait, a data race and memory corruption can occur.
- CVE-2020-36206HIGHCVSS 7.0EG 7.02021-01-26
An issue was discovered in the rusb crate before 0.7.0 for Rust. Because of a lack of Send and Sync bounds, a data race and memory corruption can occur.
- CVE-2023-45084HIGHCVSS 6.1EG 7.02023-12-05
An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, w…
- CVE-2022-26473MEDIUMCVSS 6.7EG 6.72022-10-07
In vdec fmt, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342197; Iss…
- CVE-2022-26452MEDIUMCVSS 6.7EG 6.72022-10-07
In isp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262305; Issue ID…
- CVE-2024-30387MEDIUMCVSS 6.5EG 6.52024-04-12
A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). If an interface flaps while…
- CVE-2022-25210MEDIUMCVSS 6.5EG 6.52022-02-15
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Configure permission to capture passwords of the jobs that will be configured.
- CVE-2021-36305MEDIUMCVSS 6.5EG 6.52021-11-12
Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An authenticated user of SMB on a cluster with CA could potentially exploit this vulnerability, leading to a denial of se…
- CVE-2020-3471MEDIUMCVSS 6.5EG 6.52020-11-18
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to maintain bidirectional audio despite being expelled from an active Webex session. The vulnerability is due to a sync…
- CVE-2020-14059MEDIUMCVSS 6.5EG 6.52020-06-30
An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur when processing objects in an SMP cache because of an Ipc::Mem::PageStack::pop ABA problem during access to the memory pa…
- CVE-2019-17344MEDIUMCVSS 6.5EG 6.52019-10-08
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates.
- CVE-2023-20625MEDIUMCVSS 6.4EG 6.42023-03-07
In adsp, there is a possible double free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628532; Issue ID: …
- CVE-2023-20611MEDIUMCVSS 6.4EG 6.42023-02-06
In gpu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588678; Issue ID…
- CVE-2023-20610MEDIUMCVSS 6.4EG 6.42023-02-06
In display drm, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0736346…
- CVE-2023-20607MEDIUMCVSS 6.4EG 6.42023-02-06
In ccu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07512839; Issue…
- CVE-2022-32643MEDIUMCVSS 6.4EG 6.42023-02-06
In ccd, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID…
- CVE-2022-32642MEDIUMCVSS 6.4EG 6.42023-02-06
In ccd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326547; Issue…
- CVE-2022-32648MEDIUMCVSS 6.4EG 6.42023-01-03
In disp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535964; Issue I…
- CVE-2022-32644MEDIUMCVSS 6.4EG 6.42023-01-03
In vow, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494473; Issue ID…
- CVE-2022-32613MEDIUMCVSS 6.4EG 6.42022-11-08
In vcu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07206340; Issue…
- CVE-2022-32612MEDIUMCVSS 6.4EG 6.42022-11-08
In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID…
- CVE-2022-32610MEDIUMCVSS 6.4EG 6.42022-11-08
In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203476; Issue ID…
- CVE-2022-32609MEDIUMCVSS 6.4EG 6.42022-11-08
In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203410; Issue ID…
Map vulnerabilities like CWE-662 to your infrastructure
EchelonGraph correlates every CVE — across CWE-662 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →