Vulnerability index

Browse CVEs

1,826 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Android HIGH 7.8
CVE-2016-3914

Race condition in providers/telephony/MmsProvider.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2…

Patch available
Fix from $1,950 2016-10-10
Linux Kernel HIGH 7.0
CVE-2015-0572

Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux kernel 3.x, as used in Qualc…

Fix: after 3.19.8
Fix from $1,950 2016-10-10
Xen MEDIUM 6.3
CVE-2016-7777

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM registe…

Fix: after 4.7.0
Fix from $1,600 2016-10-07
Wget HIGH 8.1
CVE-2016-7098EPSS 7%

Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass int…

Fix: after 1.17
Fix from $1,950 2016-09-26
Operations Manager CRITICAL 9.8
CVE-2016-0930

Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation…

Fix: after 1.6.18
Fix from $2,300 2016-09-18
Linux Kernel HIGH 7.4
CVE-2016-6516

Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service …

Fix: after 4.7
Fix from $1,950 2016-08-06
Linux Kernel MEDIUM 5.1
CVE-2016-6480

Race condition in the ioctl_send_fib function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 4.7 allows local users to cause a denial…

Fix: after 4.7
Fix from $1,600 2016-08-06
Linux Kernel MEDIUM 5.1
CVE-2016-6156

Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cau…

Fix: after 4.6.6
Fix from $1,600 2016-08-06
Android HIGH 7.5
CVE-2016-3760

Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairin…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.5
CVE-2016-3744

Buffer overflow in the create_pbuf function in btif/src/btif_hh.c in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, a…

Mitigation only
Fix from $1,950 2016-07-11
Ntp MEDIUM 5.9
CVE-2016-4955EPSS 9%

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association…

Fix: 4.2.8 / 4.3.93+
Fix from $1,600 2016-07-05
Ntp HIGH 7.5
CVE-2016-4954EPSS 13%

The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modi…

Fix: 4.2.8 / 4.3.93+
Fix from $1,950 2016-07-05
Symphony HIGH 7.5
CVE-2016-4309EPSS 9%

Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via t…

Patch available
Fix from $1,950 2016-06-30
Mac Os X MEDIUM 5.1
CVE-2016-1807

Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local …

Fix: 2.2.1 / 9.2.1+
Fix from $1,600 2016-05-20
Chrome MEDIUM 5.3
CVE-2016-1670

Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome b…

Fix: after 50.0.2661.87
Fix from $1,600 2016-05-14
Linux Kernel MEDIUM 5.1
CVE-2015-8839

Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk co…

Fix: after 4.4.221
Fix from $1,600 2016-05-02
Firefox HIGH 7.5
CVE-2016-2812

Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remo…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Linux Kernel MEDIUM 5.1
CVE-2016-2547

sound/core/timer.c in the Linux kernel before 4.4.1 employs a locking approach that does not consider slave timer instances, which allows local users…

Fix: after 4.4
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 5.1
CVE-2016-2546

sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race cond…

Fix: after 4.4
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 5.1
CVE-2016-2545

The snd_timer_interrupt function in sound/core/timer.c in the Linux kernel before 4.4.1 does not properly maintain a certain linked list, which allow…

Fix: after 4.4
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 5.1
CVE-2016-2544

Race condition in the queue_delete function in sound/core/seq/seq_queue.c in the Linux kernel before 4.4.1 allows local users to cause a denial of se…

Fix: after 4.4
Fix from $1,600 2016-04-27
Ubuntu Linux HIGH 7.4
CVE-2016-2069

Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure…

Fix: after 4.4
Fix from $1,950 2016-04-27
Android HIGH 8.4
CVE-2016-0848

Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to…

Patch available
Fix from $1,950 2016-04-18
Junos MEDIUM 6.7
CVE-2016-1267

Race condition in the RPC functionality in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 1…

Fix: after 12.1x44
Fix from $1,600 2016-04-15
Iphone Os HIGH 7.0
CVE-2016-1757EPSS 13%

Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context via a…

Fix: after 10.11.3
Fix from $1,950 2016-03-24
Firefox MEDIUM 6.3
CVE-2016-1975

Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might al…

Fix: after 44.0.2
Fix from $1,600 2016-03-13
Linux Kernel MEDIUM 6.8
CVE-2016-0723

Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information…

Fix: after 4.4.1
Fix from $1,600 2016-02-08
Linux Kernel MEDIUM 6.2
CVE-2015-8767

net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local use…

Fix: 4.3+
Fix from $1,600 2016-02-08
Linux Kernel MEDIUM 5.5
CVE-2015-7550

The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel before 4.3.4 does not properly use a semaphore, which allows local users t…

Fix: after 4.3.3
Fix from $1,600 2016-02-08
Webaccess HIGH 8.1
CVE-2016-0858EPSS 5%

Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via…

Fix: after 8.0
Fix from $1,950 2016-01-15