In binder_free_transaction of binder.c, there is a possible use-after-free due to a race condition. This could lead to l
Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a pers
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in l
In run of InstallPackageTask.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9,
An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe attempts to enforce access control by ad
A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Si
LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race con
The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let
It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local
There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C0
In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race co
Metadata verification and partial hash system calls by bootloader may corrupt parallel hashing state in progress resulti
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporary
In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry becau
A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Sna
Possible race condition that will cause a use-after-free when writing to two sysfs entries at nearly the same time in Sn
Race condition while accessing DMA buffer in jpeg driver in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consume
An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caus
In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could le
In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local es
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory,
Possible use-after-free issue due to a race condition while calling camera ioctl concurrently in Snapdragon Compute, Sna
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privil
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privile
Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo pr
An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subs
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwr
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A mali
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. T
cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and
In Magento prior to 1.9.4.3, Magento prior to 1.14.4.3, Magento 2.2 prior to 2.2.10, and Magento 2.3 prior to 2.3.3 or 2
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra
In the Android kernel in the mnh driver there is a race condition due to insufficient locking. This could lead to a use-
In the Android kernel in the FingerTipS touchscreen driver there is a possible memory corruption due to a race condition
In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of
In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of
In hostapd, there is a possible out of bounds write due to a race condition. This could lead to local escalation of priv
It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unp
A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 1
On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SS
GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allo
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a reque
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion
A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under rac
On Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code ex
Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is in
A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a
Frequently Asked Questions
What is CWE-362?
CWE-362 (CWE-362) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-362?
There are 2,933 CVE records associated with CWE-362 in our database. Of these, 50 are critical severity, 1207 are high severity, and 833 are medium severity.
How can I protect against CWE-362 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-362 using AI-powered security agents.
Detect CWE-362 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-362 vulnerabilities across your infrastructure.
Get Started