Vulnerability index

Browse CVEs

1,826 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Linux Kernel MEDIUM 6.9
CVE-2014-5332

Race condition in NVMap in NVIDIA Tegra Linux Kernel 3.10 allows local users to gain privileges via a crafted NVMAP_IOC_CREATE IOCTL call, which trig…

No fix yet
Fix from $1,600 2015-02-06
Firefox MEDIUM 5.0
CVE-2014-8640

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey b…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Linux Kernel MEDIUM 6.9
CVE-2014-9529

Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of se…

Fix: 3.2.67 / 3.4.107+
Fix from $1,600 2015-01-09
Acrobat Reader MEDIUM 6.4
CVE-2014-9150

Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox pr…

Fix: after 11.0.8
Fix from $1,600 2014-11-30
Ios Xr MEDIUM 5.0
CVE-2014-8005

Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a d…

Fix: after 5.1.0
Fix from $1,600 2014-11-26
Intrusion Prevention System HIGH 7.1
CVE-2014-3406

Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a …

Fix: after 7.1
Fix from $1,950 2014-10-19
Mac Os X MEDIUM 6.9
CVE-2014-4438

Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by leveraging an unattended workstati…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Nova MEDIUM 6.5
CVE-2014-8750

Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to acce…

Fix: 2014.1.4+
Fix from $1,600 2014-10-15
Asa HIGH 7.8
CVE-2014-3385

Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42), 8.4 before 8.4(7.11), 8.5 …

Mitigation only
Fix from $1,950 2014-10-10
Fedora MEDIUM 6.1
CVE-2014-7154

Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, whi…

Patch available
Fix from $1,600 2014-10-02
Kde4libs MEDIUM 6.9
CVE-2014-5033

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypas…

Fix: after 5.0
Fix from $1,600 2014-08-19
Unity HIGH 7.2
CVE-2014-5195

Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which a…

Fix: after 7.2.2
Fix from $1,950 2014-08-07
Acpi Support MEDIUM 6.9
CVE-2014-1419

Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vecto…

Fix: after 0.141
Fix from $1,600 2014-07-24
HTTP Server MEDIUM 6.8
CVE-2014-0226EPSS 86%

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buff…

Fix: 2.2.29 / 2.4.10+
Fix from $1,600 2014-07-20
Linux Kernel MEDIUM 6.9
CVE-2014-4699

The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a…

Fix: 3.2.61 / 3.4.97+
Fix from $1,600 2014-07-09
Linux Kernel MEDIUM 5.5
CVE-2014-0196 KEVEPSS 22%

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST"…

Fix: 3.2.59 / 3.4.91+
Fix from $1,600 2014-05-07
Linux Kernel HIGH 7.1
CVE-2014-2706

Race condition in the mac80211 subsystem in the Linux kernel before 3.13.7 allows remote attackers to cause a denial of service (system crash) via ne…

Fix: 3.2.56 / 3.4.84+
Fix from $1,950 2014-04-14
Nessus MEDIUM 6.9
CVE-2014-2848

A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the diss…

Fix: after 201402092115
Fix from $1,600 2014-04-11
Linux Kernel HIGH 7.1
CVE-2014-2672

Race condition in the ath_tx_aggr_sleep function in drivers/net/wireless/ath/ath9k/xmit.c in the Linux kernel before 3.13.7 allows remote attackers t…

Fix: 3.2.56 / 3.4.92+
Fix from $1,950 2014-04-01
Linux Kernel HIGH 9.3
CVE-2014-0100

Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a den…

Fix: 3.10.37 / 3.12.18+
Fix from $1,950 2014-03-11
Wireless Lan Controller Software HIGH 10.0
CVE-2014-0703

Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the administr…

Mitigation only
Fix from $1,950 2014-03-06
Mediawiki MEDIUM 5.8
CVE-2014-2243

includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon e…

Fix: after 1.19.11
Fix from $1,600 2014-03-02
Firewall Services Module Software HIGH 7.1
CVE-2014-0710

Race condition in the cut-through proxy feature in Cisco Firewall Services Module (FWSM) Software 3.x before 3.2(28) and 4.x before 4.1(15) allows re…

Mitigation only
Fix from $1,950 2014-02-22
Parcimonie HIGH 7.5
CVE-2014-1921

parcimonie before 0.8.1, when using a large keyring, sleeps for the same amount of time between fetches, which allows attackers to correlate key fetc…

Fix: after 0.7.1-1
Fix from $1,950 2014-02-14
Firefox HIGH 9.3
CVE-2014-1490

Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24…

Fix: 2.24 / 3.15.4+
Fix from $1,950 2014-02-06
Libvirt MEDIUM 6.8
CVE-2013-6458

Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functi…

Fix: after 1.2.0
Fix from $1,600 2014-01-24
Junos HIGH 7.1
CVE-2014-0616

Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 befor…

Mitigation only
Fix from $1,950 2014-01-15
Libreswan HIGH 9.3
CVE-2013-7283

Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact and attack…

Patch available
Fix from $1,950 2014-01-09
Suse Linux Enterprise For Sap Applications HIGH 7.2
CVE-2012-0426

Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an un…

Mitigation only
Fix from $1,950 2013-12-02
Quic Mobile Station Modem Kernel MEDIUM 6.9
CVE-2013-4740

goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for…

Patch available
Fix from $1,600 2013-11-12