A race condition issue discovered in Samsung Mobile Processor Exynos 9820, 980, 1080, 2100, 2200, 1280, and 1380 allows
Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this
The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download fail
The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted
In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy
The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls ne
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is
Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 co
The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect conf
Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced
Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convi
Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convin
Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to ins
Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a u
Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit
Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap c
Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially
Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who
Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who c
Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap co
The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local priv
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it shoul
Windows Hyper-V Remote Code Execution Vulnerability
Use after free in graphics fence due to a race condition while closing fence file descriptor and destroy graphics timeli
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.
Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher
crossbeam-utils provides atomics, synchronization primitives, scoped threads, and other utilities for concurrent program
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure
October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prio
An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_p
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. Th
KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session.
Windows Hyper-V Remote Code Execution Vulnerability
Frequently Asked Questions
What is CWE-362?
CWE-362 (CWE-362) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-362?
There are 2,933 CVE records associated with CWE-362 in our database. Of these, 50 are critical severity, 1207 are high severity, and 833 are medium severity.
How can I protect against CWE-362 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-362 using AI-powered security agents.
Detect CWE-362 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-362 vulnerabilities across your infrastructure.
Get Started