Show filters
374 Total Results
Displaying 51-60 of 374
Sort by:
Attacker Value
Unknown

CVE-2021-45710

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.
Attacker Value
Unknown

CVE-2017-13905

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.
Attacker Value
Unknown

CVE-2021-44733

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.
Attacker Value
Unknown

CVE-2020-35216

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages.
Attacker Value
Unknown

CVE-2021-39648

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-160822094References: Upstream kernel
Attacker Value
Unknown

CVE-2021-39642

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In synchronous_process_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195731663References: N/A
Attacker Value
Unknown

CVE-2021-0955

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-192085766
Attacker Value
Unknown

CVE-2021-0920

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel
Attacker Value
Unknown

CVE-2021-43538

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-41025

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with improper synchronization and one of authentication bypass by capture-replay, may allow a remote unauthenticated attacker to circumvent the authentication process and authenticate as a legitimate cluster peer.