Vulnerability index

Browse CVEs

1,826 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Authy 2 Factor Authentication MEDIUM 5.1
CVE-2020-24655

A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an acces…

Mitigation only
Fix from $1,600 2020-09-10
Apq8053 Firmware HIGH 8.1
CVE-2018-13903

u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sna…

Mitigation only
Fix from $1,950 2020-09-08
Chroma Sdk HIGH 8.1
CVE-2020-16602EPSS 6%

Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file …

Fix: after 3.12.17
Fix from $1,950 2020-09-02
Wolfssl HIGH 7.0
CVE-2020-15309

An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against pub…

Fix: 4.5.0+
Fix from $1,950 2020-08-21
Graphics Drivers HIGH 7.0
CVE-2020-8680

Race condition in some Intel(R) Graphics Drivers before version 15.40.45.5126 may allow an authenticated user to potentially enable escalation of pri…

Fix: 15.40.45.5126+
Fix from $1,950 2020-08-13
Ac 3165 Firmware HIGH 7.0
CVE-2020-0554

Race condition in software installer for some Intel(R) Wireless Bluetooth(R) products on Windows* 7, 8.1 and 10 may allow an unprivileged user to pot…

Fix: 21.40 / 21.70+
Fix from $1,950 2020-08-13
Enterprise Linux Atomic Host MEDIUM 6.4
CVE-2020-15706

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a fun…

Fix: after 2.04
Fix from $1,600 2020-07-29
Enterprise Linux Atomic Host MEDIUM 6.4
CVE-2020-15707

Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red…

Fix: after 2.04
Fix from $1,600 2020-07-29
Android MEDIUM 6.4
CVE-2020-0305

In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System e…

Patch available
Fix from $1,600 2020-07-17
Junos MEDIUM 6.5
CVE-2020-1641

A Race Condition vulnerability in Juniper Networks Junos OS LLDP implementation allows an attacker to cause LLDP to crash leading to a Denial of Serv…

Mitigation only
Fix from $1,600 2020-07-17
Junos HIGH 8.3
CVE-2020-1645

When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of pac…

Mitigation only
Fix from $1,950 2020-07-17
Go MEDIUM 5.9
CVE-2020-15586

Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it…

Fix: 0.203.0 / 1.13.13+
Fix from $1,600 2020-07-17
Firefox HIGH 8.8
CVE-2020-12416

A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption…

Fix: 78.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12420

When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potenti…

Fix: 68.10.0 / 78.0+
Fix from $1,950 2020-07-09
Firefox MEDIUM 5.3
CVE-2020-12405

When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerabili…

Fix: 68.9.0 / 77.0+
Fix from $1,600 2020-07-09
FreeBSD HIGH 8.1
CVE-2020-7457EPSS 33%

In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missi…

Patch available
Fix from $1,950 2020-07-09
Debian Linux HIGH 7.8
CVE-2020-15567

An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic mo…

Fix: after 4.13.1
Fix from $1,950 2020-07-07
Mate 30 Firmware MEDIUM 6.3
CVE-2020-1839

HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a race condition vulnerability. There is a timing window exists in which certa…

Fix: 10.1.0.150+
Fix from $1,600 2020-07-06
Steam Client HIGH 7.8
CVE-2020-15530

An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts …

No fix yet
Fix from $1,950 2020-07-05
Virtual Gpu Manager MEDIUM 6.3
CVE-2020-5969

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it validates a shared resource before using it, creating a race cond…

Fix: after 10.2
Fix from $1,600 2020-06-30
Fedora HIGH 7.8
CVE-2020-15396

In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local att…

Fix: after 7.0.2
Fix from $1,950 2020-06-30
Acrobat Dc HIGH 7.0
CVE-2020-9615

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier …

Fix: 15.006.30518 / 17.011.30166+
Fix from $1,950 2020-06-25
Cloud Foundation HIGH 7.5
CVE-2020-3966

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5…

Fix: 3.10 / 4.0.1+
Fix from $1,950 2020-06-25
Mir100 Firmware CRITICAL 9.8
CVE-2020-10279

MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system pre…

Fix: after 2.8.1.1
Fix from $2,300 2020-06-24
Advanced Malware Protection For Endpoints MEDIUM 6.3
CVE-2020-3350

A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the runn…

Fix: 0.102.4 / 1.12.4+
Fix from $1,600 2020-06-18
Android HIGH 7.0
CVE-2020-0218

In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a race condition. This could lead …

Patch available
Fix from $1,950 2020-06-11
Android MEDIUM 6.4
CVE-2020-0126

In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local code execution with Syst…

Patch available
Fix from $1,600 2020-06-11
Ipados HIGH 7.0
CVE-2020-9839

A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, wa…

Fix: 6.2.5 / 10.15.5+
Fix from $1,950 2020-06-09
Docker Desktop HIGH 7.8
CVE-2020-11492

An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with …

Fix: after 2.2.0.5
Fix from $1,950 2020-06-05
Identity Services Engine MEDIUM 5.9
CVE-2020-3353

A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a de…

Mitigation only
Fix from $1,600 2020-06-03