Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Gpac MEDIUM 5.5
CVE-2024-6064

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_…

Patch available
Fix from $1,600 2024-06-17
Android HIGH 8.1
CVE-2024-32929

In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no a…

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.8
CVE-2024-32900

In lwis_fence_signal of lwis_debug.c, there is a possible Use after Free due to improper locking. This could lead to local escalation of privilege fr…

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.8
CVE-2024-29787

In lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due to a use after free. This could lead to local esc…

Mitigation only
Fix from $1,950 2024-06-13
Chrome HIGH 8.8
CVE-2024-5841

Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 126.0.6478.54+
Fix from $1,950 2024-06-11
Chrome HIGH 8.8
CVE-2024-5842

Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures…

Fix: 126.0.6478.54+
Fix from $1,950 2024-06-11
Chrome HIGH 8.8
CVE-2024-5845

Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF fi…

Fix: 126.0.6478.54+
Fix from $1,950 2024-06-11
Chrome HIGH 8.8
CVE-2024-5846

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF f…

Fix: 126.0.6478.54+
Fix from $1,950 2024-06-11
Chrome HIGH 8.8
CVE-2024-5847

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF f…

Fix: 126.0.6478.54+
Fix from $1,950 2024-06-11
Chrome HIGH 8.8
CVE-2024-5831

Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 126.0.6478.54+
Fix from $1,950 2024-06-11
Chrome HIGH 8.8
CVE-2024-5832

Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 126.0.6478.54+
Fix from $1,950 2024-06-11
365 Apps HIGH 7.5
CVE-2024-30101

Microsoft Office Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-06-11
365 Apps HIGH 7.3
CVE-2024-30102

Microsoft Office Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-06-11
Windows 10 1809 HIGH 7.8
CVE-2024-30089EPSS 8%

Microsoft Streaming Service Elevation of Privilege Vulnerability

Fix: 10.0.17763.5936 / 10.0.19044.4529+
Fix from $1,950 2024-06-11
Windows 10 1507 HIGH 7.8
CVE-2024-30086

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

Fix: 10.0.10240.20680 / 10.0.14393.7070+
Fix from $1,950 2024-06-11
Windows 10 1507 CRITICAL 9.8
CVE-2024-30080EPSS 43%

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Fix: 10.0.10240.20680 / 10.0.14393.7070+
Fix from $2,300 2024-06-11
Windows 10 1507 HIGH 7.8
CVE-2024-30082

Win32k Elevation of Privilege Vulnerability

Fix: 10.0.10240.20680 / 10.0.14393.7070+
Fix from $1,950 2024-06-11
Windows Server 2012 HIGH 7.8
CVE-2024-30062

Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability

Fix: 10.0.14393.7070 / 10.0.17763.5936+
Fix from $1,950 2024-06-11
Firefox HIGH 7.5
CVE-2024-5702

Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < …

Fix: 115.12 / 125.0+
Fix from $1,950 2024-06-11
Firefox HIGH 8.1
CVE-2024-5688

If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Fi…

Fix: 115.12 / 127.0+
Fix from $1,950 2024-06-11
Firefox HIGH 7.5
CVE-2024-5694

An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerabili…

Fix: 127.0+
Fix from $1,950 2024-06-11
Debian Linux HIGH 7.8
CVE-2024-36971 KEV

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce …

Fix: 4.19.316 / 5.4.278+
Fix from $1,950 2024-06-10
Exynos 1080 Firmware HIGH 8.4
CVE-2024-32502

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 133…

Mitigation only
Fix from $1,950 2024-06-07
Exynos 850 Firmware HIGH 7.8
CVE-2024-32503

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 133…

Mitigation only
Fix from $1,950 2024-06-07
Bifrost Gpu Kernel Driver HIGH 7.8
CVE-2024-4610 KEV

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make impro…

Mitigation only
Fix from $1,950 2024-06-07
Era 100 Firmware HIGH 8.8
CVE-2024-5269

Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execu…

Mitigation only
Fix from $1,950 2024-06-06
Keyshot HIGH 7.8
CVE-2024-30375

Luxion KeyShot Viewer KSP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Fix: 2024.2+
Fix from $1,950 2024-06-06
Envoy MEDIUM 5.9
CVE-2024-34362

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` …

Fix: 1.27.6 / 1.28.4+
Fix from $1,600 2024-06-04
Envoy HIGH 7.5
CVE-2024-32974

Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with followi…

Fix: 1.27.6 / 1.28.4+
Fix from $1,950 2024-06-04
Qam8255p Firmware HIGH 7.0
CVE-2023-43543

Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object.

Patch available
Fix from $1,950 2024-06-03