Show filters
161 Total Results
Displaying 1-10 of 161
Sort by:
Attacker Value
Unknown

CVE-2020-6819

Disclosure Date: April 24, 2020 (last updated February 21, 2025)
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Attacker Value
Unknown

CVE-2020-6820

Disclosure Date: April 24, 2020 (last updated February 21, 2025)
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Attacker Value
High

CVE-2020-3941

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where Tools is installed. This vulnerability is not present in VMware Tools 11.x.y since the affected functionality is not present in VMware Tools 11.
Attacker Value
Unknown

CVE-2020-35871

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API data race.
Attacker Value
Unknown

CVE-2020-35886

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the arr crate through 2020-08-25 for Rust. An attacker can smuggle non-Sync/Send types across a thread boundary to cause a data race.
Attacker Value
Unknown

CVE-2020-35897

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the atom crate before 0.3.6 for Rust. An unsafe Send implementation allows a cross-thread data race.
Attacker Value
Unknown

CVE-2020-35874

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the internment crate through 2020-05-28 for Rust. ArcIntern::drop has a race condition and resultant use-after-free.
Attacker Value
Unknown

CVE-2020-35882

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the rocket crate before 0.4.5 for Rust. LocalRequest::clone creates more than one mutable references to the same object, possibly causing a data race.
Attacker Value
Unknown

CVE-2020-35911

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of MappedRwLockReadGuard unsoundness.
Attacker Value
Unknown

CVE-2020-35912

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of MappedRwLockWriteGuard unsoundness.