Vulnerability index

Browse CVEs

1,826 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Android HIGH 7.0
CVE-2019-2095

In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race condition. This could lead to r…

Mitigation only
Fix from $1,950 2019-06-07
Honor View 10 Firmware HIGH 7.0
CVE-2019-5216

There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C00E156R2P14T8), Honor 10 smart…

Mitigation only
Fix from $1,950 2019-06-06
Gvfs HIGH 8.1
CVE-2019-12448

An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implemen…

Fix: after 1.41.2
Fix from $1,950 2019-05-29
Debian Linux CRITICAL 9.8
CVE-2019-12450

file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progre…

Fix: after 2.61.1
Fix from $2,300 2019-05-29
Fedora HIGH 7.0
CVE-2019-10143

It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has con…

Fix: after 3.0.19
Fix from $1,950 2019-05-24
Chrome HIGH 7.5
CVE-2019-5796

Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 73.0.3683.75+
Fix from $1,950 2019-05-23
Docker HIGH 7.5
CVE-2018-15664

In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Travers…

Patch available
Fix from $1,950 2019-05-23
Banner Enterprise Identity Services HIGH 8.1
CVE-2019-8978EPSS 6%

An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 an…

No fix yet
Fix from $1,950 2019-05-14
Linux Kernel HIGH 8.1
CVE-2019-11815

An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free…

Fix: 4.4.179 / 4.9.169+
Fix from $1,950 2019-05-08
Linux Kernel HIGH 8.1
CVE-2018-20836EPSS 5%

An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/…

Fix: 3.16.72 / 3.18.140+
Fix from $1,950 2019-05-07
Groonga Httpd HIGH 7.0
CVE-2019-11675

The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root acce…

Mitigation only
Fix from $1,950 2019-05-02
Linux Kernel HIGH 7.0
CVE-2019-11486

The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.

Fix: 3.16.66 / 3.18.139+
Fix from $1,950 2019-04-23
Lxd HIGH 8.1
CVE-2015-1340

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A …

Patch available
Fix from $1,950 2019-04-22
Linux Kernel MEDIUM 6.1
CVE-2019-3837

It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded user…

Patch available
Fix from $1,600 2019-04-11
HTTP Server HIGH 7.5
CVE-2019-0217EPSS 17%

In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with val…

Fix: after 2.4.38
Fix from $1,950 2019-04-08
Safari MEDIUM 5.9
CVE-2018-4266

A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4…

Fix: 4.3.2 / 7.6+
Fix from $1,600 2019-04-03
Iphone Os HIGH 7.0
CVE-2017-7151

A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watc…

Fix: 4.2 / 10.13.2+
Fix from $1,950 2019-04-03
Access Manager HIGH 7.0
CVE-2018-18253

An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe attempts to enforce access control by adding an unprivileged user to …

Fix: after 5.4.1.1005
Fix from $1,950 2019-03-15
Webargs HIGH 8.1
CVE-2019-9710

An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-lived cache to store the pars…

Fix: 5.1.3+
Fix from $1,950 2019-03-12
Jasperreports Server HIGH 7.5
CVE-2018-18808

The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReport…

Fix: after 7.1.0
Fix from $1,950 2019-03-07
Android HIGH 7.5
CVE-2019-1992

In bta_hl_sdp_query_results of bta_hl_main.cc, there is a possible use-after-free due to a race condition. This could lead to remote code execution w…

Mitigation only
Fix from $1,950 2019-02-28
Linux Kernel HIGH 8.1
CVE-2019-6974EPSS 17%

In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading …

Fix: 3.16.64 / 3.18.136+
Fix from $1,950 2019-02-15
Android HIGH 7.0
CVE-2018-9586

In run of InstallPackageTask.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, it is possible that package v…

Patch available
Fix from $1,950 2019-02-11
Metinfo HIGH 8.1
CVE-2019-7718

An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute arbitrary PHP co…

Fix: after 6.1.3
Fix from $1,950 2019-02-11
Tmpreaper HIGH 7.0
CVE-2019-3461

Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mo…

Mitigation only
Fix from $1,950 2019-02-04
Mdm9206 Firmware HIGH 7.5
CVE-2018-11998

While processing a packet decode request in MQTT, Race condition can occur leading to an out-of-bounds access in snapdragon mobile and snapdragon wea…

Mitigation only
Fix from $1,950 2019-01-18
Debian Linux MEDIUM 6.7
CVE-2019-6133

In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization deci…

Patch available
Fix from $1,600 2019-01-11
Chrome HIGH 7.5
CVE-2018-6158

A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 68.0.3440.75+
Fix from $1,950 2019-01-09
Chrome MEDIUM 5.3
CVE-2018-16079

A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the …

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome HIGH 7.0
CVE-2017-15405

Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a mali…

Fix: 61.0.3163.113+
Fix from $1,950 2019-01-09