Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01
A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in t
In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation o
A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it pos
Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing
A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wh
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it validates a shared resource before u
HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a race condition vulnerability. There is a timing
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary fil
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time perio
A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw
In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from an
In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protec
It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For
The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptr
A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remot
Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go
An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition t
A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process t
A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated,
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.Rev
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRU
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race proble
Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directo
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords int
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, loc
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned in
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploi
A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to pote
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a play
A race condition was discovered in the Linux drivers for Nvidia graphics which allowed an attacker to exfiltrate kernel
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running bec
An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property
In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race con
Race condition in the Intel(R) Driver and Support Assistant before version 20.1.5 may allow an authenticated user to pot
A pivot_root race condition in fs/namespace.c in the Linux kernel 4.4.x before 4.4.221, 4.9.x before 4.9.221, 4.14.x bef
NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us
In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could lead to local infor
An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. Wh
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_ba
An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition betwee
An issue was discovered in the futures-util crate before 0.3.7 for Rust. MutexGuard::map can cause a data race for certa
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of MappedRwLockReadGu
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of MappedRwLockWriteG
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of RwLockReadGuard un
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of RwLockWriteGuard u
Frequently Asked Questions
What is CWE-362?
CWE-362 (CWE-362) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-362?
There are 2,933 CVE records associated with CWE-362 in our database. Of these, 50 are critical severity, 1207 are high severity, and 833 are medium severity.
How can I protect against CWE-362 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-362 using AI-powered security agents.
Detect CWE-362 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-362 vulnerabilities across your infrastructure.
Get Started