Vulnerability index

Browse CVEs

39 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Debian Linux MEDIUM 6.8
CVE-2024-24857

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity …

Fix: 6.7.12+
Fix from $1,600 2024-02-05
Debian Linux MEDIUM 5.3
CVE-2024-24858

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection o…

Fix: after 6.7.12
Fix from $1,600 2024-02-05
Debian Linux MEDIUM 6.8
CVE-2021-20316

A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify shar…

Fix: 4.15.0+
Fix from $1,600 2022-08-23
Debian Linux HIGH 7.0
CVE-2022-26357

race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associat…

Fix: 4.12.0 / 4.16.0+
Fix from $1,950 2022-04-05
Debian Linux MEDIUM 5.9
CVE-2022-24302

In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information …

Fix: 2.10.1+
Fix from $1,600 2022-03-17
Debian Linux HIGH 7.0
CVE-2021-39713

Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel

Patch available
Fix from $1,950 2022-03-16
Debian Linux HIGH 7.0
CVE-2022-23036

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23037

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23038

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23039

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23040

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23041

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.0
CVE-2022-23042

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vu…

Mitigation only
Fix from $1,950 2022-03-10
Debian Linux HIGH 7.2
CVE-2020-25719

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could b…

Patch available
Fix from $1,950 2022-02-18
Debian Linux HIGH 7.8
CVE-2021-28701

Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain …

Mitigation only
Fix from $1,950 2021-09-08
Debian Linux MEDIUM 5.9
CVE-2021-32686

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 2.11.1+
Fix from $1,600 2021-07-23
Debian Linux HIGH 7.5
CVE-2021-20181

A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause …

Fix: after 5.2.0
Fix from $1,950 2021-05-13
Debian Linux MEDIUM 6.4
CVE-2020-25651

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an il…

Fix: after 0.20.0
Fix from $1,600 2020-11-26
Debian Linux MEDIUM 6.3
CVE-2020-25653

A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged loc…

Fix: after 0.20.0
Fix from $1,600 2020-11-26
Debian Linux MEDIUM 6.3
CVE-2020-28049

An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged…

Fix: 0.19.0+
Fix from $1,600 2020-11-04
Debian Linux HIGH 7.8
CVE-2020-15567

An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic mo…

Fix: after 4.13.1
Fix from $1,950 2020-07-07
Debian Linux HIGH 7.0
CVE-2014-5255

xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A …

Fix: 5.0.1+
Fix from $1,950 2019-11-21
Debian Linux HIGH 8.1
CVE-2006-4245

archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.

Patch available
Fix from $1,950 2019-11-06
Debian Linux HIGH 7.5
CVE-2019-18421

An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable pr…

Fix: after 4.12.1
Fix from $1,950 2019-10-31
Debian Linux HIGH 7.8
CVE-2019-17341

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-wri…

Fix: after 4.11.2
Fix from $1,950 2019-10-08
Debian Linux HIGH 7.0
CVE-2019-17342

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a race con…

Fix: after 4.11.2
Fix from $1,950 2019-10-08
Debian Linux CRITICAL 9.8
CVE-2019-12450

file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progre…

Fix: after 2.61.1
Fix from $2,300 2019-05-29
Tmpreaper HIGH 7.0
CVE-2019-3461

Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mo…

Mitigation only
Fix from $1,950 2019-02-04
Debian Linux MEDIUM 6.7
CVE-2019-6133

In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization deci…

Patch available
Fix from $1,600 2019-01-11
Debian Linux MEDIUM 5.3
CVE-2018-15473EPSS 99%

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packe…

Fix: after 7.7
Fix from $1,600 2018-08-17