Vulnerability index

Browse CVEs

682 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper LockingCWE-667 × clear
Android MEDIUM 6.7
CVE-2022-26452

In isp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges…

Mitigation only
Fix from $1,600 2022-10-07
Android MEDIUM 6.7
CVE-2022-26451

In ged, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges…

Mitigation only
Fix from $1,600 2022-09-06
Linux Kernel HIGH 7.0
CVE-2022-3028

A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurr…

Fix: 4.9.327 / 4.14.292+
Fix from $1,950 2022-08-31
MariaDB MEDIUM 5.5
CVE-2022-38791

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows lo…

Fix: 10.3.36 / 10.4.26+
Fix from $1,600 2022-08-27
Linux Kernel HIGH 7.0
CVE-2022-2959

A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handlin…

Fix: 5.10.120 / 5.15.45+
Fix from $1,950 2022-08-25
Mac Os X HIGH 7.8
CVE-2022-32811

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Upd…

Fix: 10.15.7 / 11.6.8+
Fix from $1,950 2022-08-24
Android MEDIUM 6.7
CVE-2022-20376

In trusty_log_seq_start of trusty-log.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege…

Mitigation only
Fix from $1,600 2022-08-11
Android MEDIUM 6.4
CVE-2022-20371

In dm_bow_dtr and related functions of dm-bow.c, there is a possible use after free due to a race condition. This could lead to local escalation of p…

Mitigation only
Fix from $1,600 2022-08-11
Android MEDIUM 6.7
CVE-2022-21775

In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution p…

Mitigation only
Fix from $1,600 2022-07-06
Q03udecpu Firmware HIGH 7.5
CVE-2022-24946

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MEL…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.0
CVE-2022-20141

In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege when openi…

Mitigation only
Fix from $1,950 2022-06-15
Android MEDIUM 6.7
CVE-2022-20153

In rcu_cblist_dequeue of rcu_segcblist.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privileg…

Mitigation only
Fix from $1,600 2022-06-15
MariaDB MEDIUM 5.5
CVE-2022-31621

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (stream_ctxt->dest_file == N…

Fix: 10.2.41 / 10.3.32+
Fix from $1,600 2022-05-25
MariaDB MEDIUM 5.5
CVE-2022-31622

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (pthread_create returns a no…

Fix: 10.2.42 / 10.3.33+
Fix from $1,600 2022-05-25
MariaDB MEDIUM 5.5
CVE-2022-31623

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (i.e., going to the err labe…

Fix: 10.2.42 / 10.3.33+
Fix from $1,600 2022-05-25
MariaDB MEDIUM 5.5
CVE-2022-31624

MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the he…

Fix: 10.2.41 / 10.3.32+
Fix from $1,600 2022-05-25
Android HIGH 7.8
CVE-2021-39801

In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no add…

Patch available
Fix from $1,950 2022-04-12
Cortx S3 Server HIGH 7.5
CVE-2021-43429

A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->l…

Patch available
Fix from $1,950 2022-04-07
Debian Linux MEDIUM 5.6
CVE-2022-26356

Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was nam…

Fix: 4.12.0 / 4.14.0+
Fix from $1,600 2022-04-05
Libvirt MEDIUM 6.5
CVE-2021-4147

A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash,…

Fix: 2.33.0+
Fix from $1,600 2022-03-25
Linux Kernel MEDIUM 5.5
CVE-2021-4149

A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this fla…

Fix: 5.15+
Fix from $1,600 2022-03-23
Libvirt MEDIUM 6.5
CVE-2021-3667

An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function w…

Fix: after 7.5.0
Fix from $1,600 2022-03-02
Gnome Shell MEDIUM 6.1
CVE-2021-20315

A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window …

Fix: 3.32.2+
Fix from $1,600 2022-02-18
Junos HIGH 7.5
CVE-2022-22175

An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated networked attacke…

Mitigation only
Fix from $1,950 2022-01-19
Debian Linux HIGH 7.5
CVE-2021-41141

PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RT…

Fix: after 2.11.1
Fix from $1,950 2022-01-04
Android MEDIUM 6.7
CVE-2022-20016

In vow driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution …

Mitigation only
Fix from $1,600 2022-01-04
Android HIGH 7.8
CVE-2021-39640

In __dwc3_gadget_ep0_queue of ep0.c, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privileg…

Patch available
Fix from $1,950 2021-12-15
Android MEDIUM 6.7
CVE-2021-39649

In regmap_exit of regmap.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kerne…

Patch available
Fix from $1,600 2021-12-15
Android MEDIUM 6.7
CVE-2021-39656

In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in th…

Patch available
Fix from $1,600 2021-12-15
Tensorflow MEDIUM 5.5
CVE-2021-41213

TensorFlow is an open source platform for machine learning. In affected versions the code behind `tf.function` API can be made to deadlock when two `…

Fix: 2.4.4 / 2.5.2+
Fix from $1,600 2021-11-05