CWE-368Base

Context Switching Race Condition

Draft in the CWE catalog · 4 CVEs mapped

4
CVEs mapped
9.1
Median CVSS
What it is

A product performs a series of non-atomic actions to switch between contexts that cross privilege or other security boundaries, but a race condition allows an attacker to modify or misrepresent the product's behavior during the switch.

Recent examples
10.0cvss
CVE-2022-21806

A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h

🚨 A crafty set of network packets is all it takes to seize control of your Anker Eufy Homebase 2! 🔥 Think of this vulnerability like a sneaky delivery driver who can drop off a package that doesn't belong at your door — once it’s there, they can waltz right in and make themselves at home! An attacker could remotely execute code on your device, which means they could potentially access and control your home network. This could lead to catastrophic consequences, like invading your privacy or creating an entry point for further attacks on other devices. Yikes!

CRITICAL
2%
epss
8.1cvss
CVE-2021-32025

An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX…

An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX OS for Medical version 2.0.0 could allow an attacker to potentially access data, modify behavior, or permanently crash the system.

HIGHno explanation yet
0%
epss
10.0cvss
CVE-2021-21941

A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h

🚨 A clever use-after-free vulnerability in Anker Eufy Homebase 2 could give attackers the keys to your smart home! 🔥 Think of it like a delivery driver who still accepts packages even after their job is done — the system trusts the packets without verifying if it should. These rogue packets can lead to unexpected chaos! An attacker could execute arbitrary code remotely, potentially turning your smart home into a playground for mischief—accessing cameras, tampering with settings, or even knocking on your door uninvited! That's absolutely devastating for your privacy and security.

CRITICAL
2%
epss
The record
Technical detail
CWE ID
CWE-368
Abstraction
Base
Structure
Simple
Status
Draft