Vulnerability index

Browse CVEs

1,826 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Android MEDIUM 6.4
CVE-2020-10845

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a race condition leading to a use-after-free in…

Mitigation only
Fix from $1,600 2020-03-24
Android HIGH 7.0
CVE-2020-10843

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets) software. There are race conditions in the hdcp2 …

Mitigation only
Fix from $1,950 2020-03-24
Ansible HIGH 7.1
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a …

Fix: 2.7.17 / 2.8.9+
Fix from $1,950 2020-03-24
Janus MEDIUM 5.9
CVE-2020-10576

An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server cras…

Fix: after 0.9.1
Fix from $1,600 2020-03-14
Ansible MEDIUM 5.0
CVE-2020-1733

A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged bec…

Fix: 2.8.8+
Fix from $1,600 2020-03-11
Android MEDIUM 6.4
CVE-2020-0066

In the netlink driver, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System …

Mitigation only
Fix from $1,600 2020-03-10
Android MEDIUM 6.4
CVE-2020-0045

In StatsService::command of StatsService.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of pri…

Mitigation only
Fix from $1,600 2020-03-10
Froxlor MEDIUM 5.5
CVE-2020-10237

An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting prop…

Fix: after 0.10.15
Fix from $1,600 2020-03-09
Fedora HIGH 7.0
CVE-2020-10174

init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/times…

Fix: 20.03+
Fix from $1,950 2020-03-05
Apq8009 Firmware HIGH 7.0
CVE-2019-14072

Unhandled paging request is observed due to dereferencing an already freed object because of race condition between sparse free and sparse bind ioctl…

Mitigation only
Fix from $1,950 2020-03-05
Ipados HIGH 7.0
CVE-2020-3831

A race condition was addressed with improved locking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. An application may be able to execute arbi…

Fix: 13.3.1+
Fix from $1,950 2020-02-27
Gogs MEDIUM 5.9
CVE-2020-9329

Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.

Fix: after 0.11.91
Fix from $1,600 2020-02-21
Linux Kernel HIGH 7.0
CVE-2011-0699

Integer signedness error in the btrfs_ioctl_space_info function in the Linux kernel 2.6.37 allows local users to cause a denial of service (heap-base…

Patch available
Fix from $1,950 2020-02-20
Unified Contact Center Enterprise MEDIUM 5.9
CVE-2020-3163

A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remote attacker to cause a denial …

Fix: 12.5+
Fix from $1,600 2020-02-19
Nip6800 Firmware MEDIUM 5.3
CVE-2020-1814

Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600,…

Mitigation only
Fix from $1,600 2020-02-18
Itop HIGH 8.1
CVE-2019-11215

In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.data…

Fix: after 2.6.0
Fix from $1,950 2020-02-14
Android HIGH 7.0
CVE-2020-0030

In binder_thread_release of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wi…

Patch available
Fix from $1,950 2020-02-13
Spritebackup HIGH 7.0
CVE-2013-3685

A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones…

No fix yet
Fix from $1,950 2020-02-12
Node.js HIGH 8.1
CVE-2014-9748

The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the loc…

Fix: 0.10.46 / 0.12.15+
Fix from $1,950 2020-02-11
Chrome HIGH 8.8
CVE-2020-6388

Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 80.0.3987.87+
Fix from $1,950 2020-02-11
Bromium MEDIUM 6.3
CVE-2019-18567

Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denia…

Fix: after 4.1.7
Fix from $1,600 2020-02-03
Fish HIGH 7.0
CVE-2014-2906

The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrar…

Fix: 2.1.1+
Fix from $1,950 2020-01-28
Fish HIGH 7.0
CVE-2014-3856

The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privilege…

Fix: 2.1.1+
Fix from $1,950 2020-01-28
Squid Analysis Report Generator HIGH 7.0
CVE-2019-18932

log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tm…

Fix: after 2.3.11
Fix from $1,950 2020-01-21
Portage MEDIUM 5.5
CVE-2019-20384

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to th…

Fix: after 2.3.84
Fix from $1,600 2020-01-21
Sinamics Perfect Harmony Gh180 Firmware MEDIUM 6.8
CVE-2019-19278

A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR32..-.....-.... MLFB 6SR4...-.....-.... MLFB 6SR5...-.....-.... …

Mitigation only
Fix from $1,600 2020-01-16
Tools HIGH 7.0
CVE-2020-3941

The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where To…

Fix: 11.0.0+
Fix from $1,950 2020-01-15
Linux Kernel MEDIUM 5.9
CVE-2007-4774

The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptraced process with SIGCONT sig…

Fix: after 2.4.35
Fix from $1,600 2020-01-15
Firefox MEDIUM 5.3
CVE-2019-17021

During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the pare…

Fix: 68.4 / 72.0+
Fix from $1,600 2020-01-08
Firefox HIGH 7.5
CVE-2019-17010

Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a u…

Fix: 68.3 / 71.0+
Fix from $1,950 2020-01-08