Vulnerability index

Browse CVEs

1,826 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
MEDIUM 6.9 CVE-2008-1669 Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in p… Linux Kernel Patch available Fix from $1,6002008-05-08 MEDIUM 6.9 CVE-2008-1375 Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local user… Linux Kernel 2.6.24.6+ Fix from $1,6002008-05-02 MEDIUM 6.9 CVE-2008-1570 Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating th… Policyd Weight Mitigation only Fix from $1,6002008-03-31 HIGH 7.2 CVE-2008-0055 Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permission… Mac Os X Patch available Fix from $1,9502008-03-18 MEDIUM 5.8 CVE-2008-0058 Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbi… Mac Os X Patch available Fix from $1,6002008-03-18 MEDIUM 5.8 CVE-2008-0059 Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file,… Mac Os X Patch available Fix from $1,6002008-03-18 HIGH 9.3 CVE-2008-0379EPSS 9% Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to … Crystal Reports Xi No fix yet Fix from $1,9502008-01-22 HIGH 9.3 CVE-2007-6429 Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request … Evi after 1.4 Fix from $1,9502008-01-18 MEDIUM 6.6 CVE-2007-5847 Race condition in the CFURLWriteDataAndPropertiesToResource API in Core Foundation in Apple Mac OS X 10.4.11 creates files with insecure permissions,… Mac Os X Mitigation only Fix from $1,6002007-12-19 HIGH 7.6 CVE-2007-6180 Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL … Solaris Patch available Fix from $1,9502007-11-30 MEDIUM 6.8 CVE-2007-6077 The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEF… Rails Patch available Fix from $1,6002007-11-21 MEDIUM 5.8 CVE-2007-5154 Session fixation vulnerability in Aipo and Aipo ASP 3.0.1.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors. Aipo after 3.0.1.0 Fix from $1,6002007-10-01 MEDIUM 6.9 CVE-2007-0997 Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (sys… Linux Kernel Mitigation only Fix from $1,6002007-09-18 HIGH 7.6 CVE-2007-3970EPSS 6% Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap co… Nod32 Antivirus 2.2289+ Fix from $1,9502007-07-25 HIGH 7.1 CVE-2007-3091EPSS 28% Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2;… Windows 2003 Server Patch available Fix from $1,9502007-06-06 MEDIUM 6.2 CVE-2007-1741 Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to g… HTTP Server Mitigation only Fix from $1,6002007-04-13 MEDIUM 6.8 CVE-2007-1249 MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows … C1 Financial Services Mitigation only Fix from $1,6002007-03-03 HIGH 9.3 CVE-2007-0099EPSS 25% Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attacker… Xml Core Services Patch available Fix from $1,9502007-01-08 MEDIUM 6.2 CVE-2006-4801 Race condition in Deja Vu, as used in Roxio Toast Titanium 7 and possibly other products, allows local users to execute arbitrary code via temporary … Toast No fix yet Fix from $1,6002006-09-14 MEDIUM 5.1 CVE-2006-2094EPSS 23% Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, … Ie No fix yet Fix from $1,6002006-04-29 MEDIUM 5.1 CVE-2005-3240EPSS 6% Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a use… Ie Mitigation only Fix from $1,6002005-12-31 MEDIUM 6.9 CVE-2004-2697 The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a comman… Aix No fix yet Fix from $1,6002004-12-31 MEDIUM 6.9 CVE-2004-2698 Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) an… Imwheel after 1.0.0pre11 Fix from $1,6002004-12-31 HIGH 7.6 CVE-2003-1562EPSS 6% sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay afte… Openssh Mitigation only Fix from $1,9502003-12-31 HIGH 10.0 CVE-2002-2374 Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files." Patchpro Patch available Fix from $1,9502002-12-31 MEDIUM 6.2 CVE-2000-0864 Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary … Esound Patch available Fix from $1,6002000-11-14