An issue was discovered in the concread crate before 0.2.6 for Rust. Attackers can cause an ARCache<K,V> data race by se
An issue was discovered in the arr crate through 2020-08-25 for Rust. An attacker can smuggle non-Sync/Send types across
An issue was discovered in the atom crate before 0.3.6 for Rust. An unsafe Send implementation allows a cross-thread dat
In OutputBuffersArray::realloc of CCodecBuffers.cpp, there is a possible heap disclosure due to a race condition. This c
An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a cl
An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session man
In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline cou
The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to h
In TimeCheck::TimeCheckThread::threadLoop of TimeCheck.cpp, there is a possible use-after-free due to a race condition.
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using
Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X1
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (
A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, S
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correct
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while
In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lea
The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Communit
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can
An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup functio
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because
An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_d
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race conditio
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Ta
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the a
modules/luksbootkeyfile/main.py in Calamares versions 3.1 through 3.2.10 has a race condition between the time when the
A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to wr
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security v
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set
dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during install
eDeploy has tmp file race condition flaws
Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privi
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privil
Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R
A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap
While processing a packet decode request in MQTT, Race condition can occur leading to an out-of-bounds access in snapdra
In bta_hl_sdp_query_results of bta_hl_main.cc, there is a possible use-after-free due to a race condition. This could le
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded serve
In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially explo
In createEffect of AudioFlinger.cpp, there is a possible memory corruption due to a race condition. This could lead to l
In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE be
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra
A race condition existed during the installation of iTunes for Windows. This was addressed with improved state handling.
A race condition existed during the installation of iCloud for Windows. This was addressed with improved state handling.
Frequently Asked Questions
What is CWE-362?
CWE-362 (CWE-362) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-362?
There are 2,933 CVE records associated with CWE-362 in our database. Of these, 50 are critical severity, 1207 are high severity, and 833 are medium severity.
How can I protect against CWE-362 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-362 using AI-powered security agents.
Detect CWE-362 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-362 vulnerabilities across your infrastructure.
Get Started