Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-667

MITRE ↗

CWE-667

7
CRITICAL
173
HIGH
509
MEDIUM
10
LOW
702 CVEs · Page 13/15
6.7
CVE-2022-21775

In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of priv

6.7
CVE-2022-20376

In trusty_log_seq_start of trusty-log.c, there is a possible use after free due to improper locking. This could lead to

6.7
CVE-2022-26451

In ged, there is a possible use after free due to improper locking. This could lead to local escalation of privilege wit

6.7
CVE-2022-26452

In isp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege wit

6.7
CVE-2022-26473

In vdec fmt, there is a possible use after free due to improper locking. This could lead to local escalation of privileg

6.5
CVE-2021-3667

An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePool

6.5
CVE-2021-4147

A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on t

6.5
CVE-2022-39358

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was po

6.4
CVE-2022-20371

In dm_bow_dtr and related functions of dm-bow.c, there is a possible use after free due to a race condition. This could

6.1
CVE-2021-20315

A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "

5.9
CVE-2021-41141

PJSIP is a free and open source multimedia communication library written in the C language implementing standard based p

5.6
CVE-2022-26356

Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_D

5.5
CVE-2021-4149

A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock op

5.5
CVE-2022-31621

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs

5.5
CVE-2022-31622

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs

5.5
CVE-2022-31623

MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs

5.5
CVE-2022-31624

MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c me

5.5
CVE-2022-38791

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream w

5.5
CVE-2022-38690

In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of serv

5.5
CVE-2022-4129

A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can

5.5
CVE-2022-39131

In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of serv

5.5
CVE-2022-42775

In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of serv

5.5
CVE-2022-42328

Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text expl

5.5
CVE-2022-42329

Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text expl

5.5
CVE-2021-43395

An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, Op

4.7
CVE-2022-3303

A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL poi

4.4
CVE-2021-0147

Improper locking in the Power Management Controller (PMC) for some Intel Chipset firmware before versions pmc_fw_lbg_c1-

4.4
CVE-2021-3735

A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while

4.3
CVE-2022-0897

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the drive

8.6
CVE-2021-1622

A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Ro

8.4
CVE-2020-11284

Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the me

7.8
CVE-2021-0529

In memory management driver, there is a possible memory corruption due to improper locking. This could lead to local esc

7.8
CVE-2021-39640

In __dwc3_gadget_ep0_queue of ep0.c, there is a possible out of bounds write due to improper locking. This could lead to

7.5
CVE-2021-31422

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-4

7.5
CVE-2021-29509

Puma is a concurrent HTTP 1.1 server for Ruby/Rack applications. The fix for CVE-2019-16770 was incomplete. The original

7.0
CVE-2021-26708

A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK

7.0
CVE-2021-1782 KEV

A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-00

6.7
CVE-2021-0625

In ccu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege

6.7
CVE-2021-39649

In regmap_exit of regmap.c, there is a possible use-after-free due to improper locking. This could lead to local escalat

6.7
CVE-2021-39656

In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local

6.5
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image

6.5
CVE-2021-31785

The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of m

6.5
CVE-2021-31786

The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection

5.9
CVE-2020-36220

An issue was discovered in the va-ts crate before 0.0.4 for Rust. Because Demuxer<T> omits a required T: Send bound, a d

5.7
CVE-2021-31611

The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle an out-of-order

5.6
CVE-2021-31427

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt

5.5
CVE-2021-28951

An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of se

5.5
CVE-2021-38203

btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trig

5.5
CVE-2021-1123

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can deadlock, which may

5.5
CVE-2021-41213

TensorFlow is an open source platform for machine learning. In affected versions the code behind `tf.function` API can b

Frequently Asked Questions

What is CWE-667?

CWE-667 (CWE-667) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-667?

There are 851 CVE records associated with CWE-667 in our database. Of these, 7 are critical severity, 173 are high severity, and 509 are medium severity.

How can I protect against CWE-667 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-667 using AI-powered security agents.

Detect CWE-667 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-667 vulnerabilities across your infrastructure.

Get Started