Windows Hyper-V Remote Code Execution Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation,
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel
Windows Hyper-V Remote Code Execution Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
A race condition was addressed with improved locking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 an
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
A privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a ra
A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other
In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to ga
Windows Scripting Languages Remote Code Execution Vulnerability
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could ha
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authenticat
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket an
If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUt
Windows Kernel Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
In phTmlNfc_Init and phTmlNfc_CleanUp of phTmlNfc.cc, there is a possible use after free due to a race condition. This c
In init of vendor_graphicbuffer_meta.cpp, there is a possible use after free due to a race condition. This could lead to
A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in
Local privilege escalation due to race condition on application startup. The following products are affected: Acronis Cy
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the
A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls i
Windows ALPC Elevation of Privilege Vulnerability
Windows ALPC Elevation of Privilege Vulnerability
Windows Update Stack Elevation of Privilege Vulnerability
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t
In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race conditi
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kern
race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a tr
Windows ALPC Elevation of Privilege Vulnerability
Windows ALPC Elevation of Privilege Vulnerability
Windows Work Folder Service Elevation of Privilege Vulnerability
Windows File Explorer Elevation of Privilege Vulnerability
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inj
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This
Frequently Asked Questions
What is CWE-362?
CWE-362 (CWE-362) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-362?
There are 2,933 CVE records associated with CWE-362 in our database. Of these, 50 are critical severity, 1207 are high severity, and 833 are medium severity.
How can I protect against CWE-362 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-362 using AI-powered security agents.
Detect CWE-362 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-362 vulnerabilities across your infrastructure.
Get Started