Vulnerability index

Browse CVEs

1,826 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Elasticsearch MEDIUM 6.5
CVE-2018-17244

Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, L…

Fix: after 6.4.2
Fix from $1,600 2018-12-20
Veraport G3 HIGH 8.1
CVE-2018-5198

In Veraport G3 ALL on MacOS, a race condition when calling the Veraport API allow remote attacker to cause arbitrary file download and execution. Thi…

Mitigation only
Fix from $1,950 2018-12-20
Fedora HIGH 7.8
CVE-2018-16867

A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp…

Fix: after 3.0.0
Fix from $1,950 2018-12-12
Android MEDIUM 6.4
CVE-2018-9519

In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,600 2018-12-07
Big Ip Access Policy Manager HIGH 7.0
CVE-2018-15332

The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivilege…

Fix: after 13.1.1
Fix from $1,950 2018-12-06
Yoast Seo MEDIUM 6.6
CVE-2018-19370

A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordP…

Fix: after 9.2.0
Fix from $1,600 2018-11-28
Android HIGH 7.0
CVE-2018-9539

In the ClearKey CAS descrambler, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no…

Patch available
Fix from $1,950 2018-11-14
Chrome HIGH 7.5
CVE-2018-6061

A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit …

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Ubuntu Linux HIGH 7.0
CVE-2018-15687

A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are…

Fix: 240+
Fix from $1,950 2018-10-26
Linux Kernel HIGH 8.1
CVE-2018-18559

In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET sock…

Fix: 3.2.100 / 3.15+
Fix from $1,950 2018-10-22
Service Governance Framework MEDIUM 5.9
CVE-2018-7110

A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condi…

Mitigation only
Fix from $1,600 2018-10-17
Ios Xe MEDIUM 6.1
CVE-2018-0480

A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to …

Mitigation only
Fix from $1,600 2018-10-05
Linux Kernel MEDIUM 5.5
CVE-2018-17972

An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may i…

Fix: after 4.18.11
Fix from $1,600 2018-10-03
310s 14isk Firmware MEDIUM 5.9
CVE-2018-9069

In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, pot…

Fix: 1.15 / 2wcn38ww+
Fix from $1,600 2018-10-02
Otcms HIGH 8.1
CVE-2018-17364

OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.

No fix yet
Fix from $1,950 2018-09-23
Android HIGH 7.0
CVE-2018-5905

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a race condition while accessing num of c…

Patch available
Fix from $1,950 2018-09-19
Android HIGH 7.0
CVE-2018-11818

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, LUT configuration is passed down to drive…

Patch available
Fix from $1,950 2018-09-18
Gitolite HIGH 8.1
CVE-2018-16976

Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the proc…

Fix: 3.6.9+
Fix from $1,950 2018-09-12
Linux Kernel HIGH 7.0
CVE-2018-14625

A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condi…

Patch available
Fix from $1,950 2018-09-10
Debian Linux MEDIUM 5.3
CVE-2018-15473EPSS 99%

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packe…

Fix: after 7.7
Fix from $1,600 2018-08-17
Charles HIGH 7.0
CVE-2017-15358

Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving th…

Fix: 4.2.1+
Fix from $1,950 2018-08-03
Tomcat MEDIUM 5.9
CVE-2018-8037EPSS 12%

If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that cou…

Fix: after 9.0.9
Fix from $1,600 2018-08-02
Openstack MEDIUM 5.9
CVE-2017-7543

A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1,…

Fix: 7.2.0-12.1 / 8.3.0-11.1+
Fix from $1,600 2018-07-26
Linux Kernel HIGH 7.0
CVE-2018-5873

An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a U…

Fix: 4.1.50 / 4.4.116+
Fix from $1,950 2018-07-06
Android HIGH 7.0
CVE-2018-5853

A race condition exists in a driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before…

Mitigation only
Fix from $1,950 2018-07-06
Android HIGH 7.0
CVE-2018-5859

Due to a race condition in the MDSS MDP driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Andr…

Patch available
Fix from $1,950 2018-07-06
Android HIGH 7.0
CVE-2018-5832

Due to a race condition in a camera driver ioctl handler in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QR…

Mitigation only
Fix from $1,950 2018-07-06
Android HIGH 7.0
CVE-2017-15856

Due to a race condition while processing the power stats debug file to read status, a double free condition can occur in Android releases from CAF us…

Patch available
Fix from $1,950 2018-07-06
Onos MEDIUM 6.8
CVE-2018-12691

Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows att…

Fix: after 1.13.0
Fix from $1,600 2018-07-05
Hbase HIGH 8.1
CVE-2018-8025

CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition wh…

Fix: after 2.0.0
Fix from $1,950 2018-06-27