Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-362

MITRE ↗

CWE-362

50
CRITICAL
1,207
HIGH
833
MEDIUM
77
LOW
2,192 CVEs · Page 28/44
7.8
CVE-2022-24537

Windows Hyper-V Remote Code Execution Vulnerability

7.8
CVE-2022-29113

Windows Digital Media Receiver Elevation of Privilege Vulnerability

7.8
CVE-2021-3922

A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation,

7.8
CVE-2022-34892

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel

7.8
CVE-2022-34696

Windows Hyper-V Remote Code Execution Vulnerability

7.8
CVE-2022-41045

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

7.8
CVE-2022-41093

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

7.8
CVE-2022-41100

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

7.5
CVE-2022-26701

A race condition was addressed with improved locking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 an

7.5
CVE-2022-35796

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

7.5
CVE-2022-24949

A privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a ra

7.5
CVE-2022-24950

A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other

7.5
CVE-2016-20015

In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to ga

7.5
CVE-2022-41118

Windows Scripting Languages Remote Code Execution Vulnerability

7.5
CVE-2022-22737

Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could ha

7.2
CVE-2020-25719

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authenticat

7.1
CVE-2021-3752

A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket an

7.1
CVE-2022-42930

If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUt

7.0
CVE-2022-21881

Windows Kernel Elevation of Privilege Vulnerability

7.0
CVE-2022-21896

Windows DWM Core Library Elevation of Privilege Vulnerability

7.0
CVE-2021-39629

In phTmlNfc_Init and phTmlNfc_CleanUp of phTmlNfc.cc, there is a possible use after free due to a race condition. This c

7.0
CVE-2021-39679

In init of vendor_graphicbuffer_meta.cpp, there is a possible use after free due to a race condition. This could lead to

7.0
CVE-2021-4083

A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in

7.0
CVE-2022-24114

Local privilege escalation due to race condition on application startup. The following products are affected: Acronis Cy

7.0
CVE-2021-3609

.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the

7.0
CVE-2021-3640

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls i

7.0
CVE-2022-23283

Windows ALPC Elevation of Privilege Vulnerability

7.0
CVE-2022-24505

Windows ALPC Elevation of Privilege Vulnerability

7.0
CVE-2022-24525

Windows Update Stack Elevation of Privilege Vulnerability

7.0
CVE-2022-23036

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t

7.0
CVE-2022-23037

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t

7.0
CVE-2022-23038

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t

7.0
CVE-2022-23039

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t

7.0
CVE-2022-23040

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t

7.0
CVE-2022-23041

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t

7.0
CVE-2022-23042

Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t

7.0
CVE-2021-39686

In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race conditi

7.0
CVE-2021-39713

Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel

7.0
CVE-2021-4202

A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kern

7.0
CVE-2022-26357

race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits

7.0
CVE-2022-28796

jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a tr

7.0
CVE-2022-24482

Windows ALPC Elevation of Privilege Vulnerability

7.0
CVE-2022-24540

Windows ALPC Elevation of Privilege Vulnerability

7.0
CVE-2022-26807

Windows Work Folder Service Elevation of Privilege Vulnerability

7.0
CVE-2022-26808

Windows File Explorer Elevation of Privilege Vulnerability

7.0
CVE-2022-26827

Windows File Server Resource Management Service Elevation of Privilege Vulnerability

7.0
CVE-2022-26828

Windows Bluetooth Driver Elevation of Privilege Vulnerability

7.0
CVE-2022-26904 KEV

Windows User Profile Service Elevation of Privilege Vulnerability

7.0
CVE-2022-29527

Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inj

7.0
CVE-2022-29582

In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This

Frequently Asked Questions

What is CWE-362?

CWE-362 (CWE-362) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-362?

There are 2,933 CVE records associated with CWE-362 in our database. Of these, 50 are critical severity, 1207 are high severity, and 833 are medium severity.

How can I protect against CWE-362 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-362 using AI-powered security agents.

Detect CWE-362 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-362 vulnerabilities across your infrastructure.

Get Started