Total
1264 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-10174 | 3 Canonical, Fedoraproject, Timeshift Project | 3 Ubuntu Linux, Fedora, Timeshift | 2022-01-01 | 6.9 MEDIUM | 7.0 HIGH |
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by unprivileged users. Because Timeshift also executes scripts under this location, an attacker can attempt to win a race condition to replace scripts created by Timeshift with attacker-controlled scripts. Upon success, an attacker-controlled script is executed with full root privileges. This logic is practically always triggered when Timeshift runs regardless of the command-line arguments used. | |||||
CVE-2021-30982 | 1 Apple | 2 Mac Os X, Macos | 2021-12-30 | 4.3 MEDIUM | 5.9 MEDIUM |
A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A remote attacker may be able to cause unexpected application termination or heap corruption. | |||||
CVE-2021-30955 | 1 Apple | 5 Ipados, Iphone Os, Macos and 2 more | 2021-12-29 | 7.6 HIGH | 7.0 HIGH |
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. A malicious application may be able to execute arbitrary code with kernel privileges. | |||||
CVE-2021-30996 | 1 Apple | 3 Ipados, Iphone Os, Macos | 2021-12-29 | 7.6 HIGH | 7.0 HIGH |
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2. A malicious application may be able to execute arbitrary code with kernel privileges. | |||||
CVE-2020-35216 | 1 Atomix | 1 Atomix | 2021-12-21 | 4.3 MEDIUM | 5.9 MEDIUM |
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages. | |||||
CVE-2021-39642 | 1 Google | 1 Android | 2021-12-20 | 4.4 MEDIUM | 6.4 MEDIUM |
In synchronous_process_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195731663References: N/A | |||||
CVE-2021-0955 | 1 Google | 1 Android | 2021-12-20 | 6.9 MEDIUM | 7.0 HIGH |
In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-192085766 | |||||
CVE-2020-12387 | 1 Mozilla | 3 Firefox, Firefox Esr, Thunderbird | 2021-12-14 | 6.8 MEDIUM | 8.1 HIGH |
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. | |||||
CVE-2021-37069 | 1 Huawei | 3 Emui, Harmonyos, Magic Ui | 2021-12-09 | 5.8 MEDIUM | 7.4 HIGH |
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected. | |||||
CVE-2021-22428 | 1 Huawei | 2 Emui, Magic Ui | 2021-12-09 | 6.8 MEDIUM | 8.1 HIGH |
There is an Incomplete Cleanup Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass. | |||||
CVE-2021-37074 | 1 Huawei | 3 Emui, Harmonyos, Magic Ui | 2021-12-09 | 9.3 HIGH | 8.1 HIGH |
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation. | |||||
CVE-2021-22427 | 1 Huawei | 2 Emui, Magic Ui | 2021-12-09 | 6.8 MEDIUM | 8.1 HIGH |
There is a Heap-based Buffer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass. | |||||
CVE-2021-22384 | 1 Huawei | 2 Emui, Magic Ui | 2021-12-09 | 6.8 MEDIUM | 8.1 HIGH |
There is an Information Disclosure Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass. | |||||
CVE-2021-37073 | 1 Huawei | 1 Harmonyos | 2021-12-09 | 4.3 MEDIUM | 3.7 LOW |
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the detection result is tampered with. | |||||
CVE-2021-37082 | 1 Huawei | 1 Harmonyos | 2021-12-09 | 4.3 MEDIUM | 5.9 MEDIUM |
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash. | |||||
CVE-2021-37085 | 1 Huawei | 1 Harmonyos | 2021-12-09 | 7.1 HIGH | 5.9 MEDIUM |
There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service. | |||||
CVE-2021-44513 | 1 Tmate | 1 Tmate-ssh-server | 2021-12-08 | 4.4 MEDIUM | 7.0 HIGH |
Insecure creation of temporary directories in tmate-ssh-server 2.3.0 allows a local attacker to compromise the integrity of session handling. | |||||
CVE-2021-30603 | 2 Fedoraproject, Google | 2 Fedora, Chrome | 2021-11-30 | 5.1 MEDIUM | 7.5 HIGH |
Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |||||
CVE-2021-36808 | 1 Sophos | 1 Sophos Secure Workspace | 2021-11-29 | 4.4 MEDIUM | 7.0 HIGH |
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115. | |||||
CVE-2021-0870 | 1 Google | 1 Android | 2021-11-29 | 9.3 HIGH | 8.1 HIGH |
In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-192472262 |