Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Linux Kernel HIGH 7.8
CVE-2023-52438

In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used dur…

Fix: 5.4.268 / 5.10.209+
Fix from $1,950 2024-02-20
Fedora CRITICAL 9.8
CVE-2024-23310

A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A spe…

No fix yet
Fix from $2,300 2024-02-20
Nav2 CRITICAL 9.1
CVE-2024-25198

Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2…

Fix: after 1.1.17
Fix from $2,300 2024-02-20
Nav2 HIGH 8.1
CVE-2024-25199

Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versio…

Fix: after 1.1.17
Fix from $1,950 2024-02-20
Libdicom CRITICAL 9.8
CVE-2024-24793

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM f…

No fix yet
Fix from $2,300 2024-02-20
Libdicom CRITICAL 9.8
CVE-2024-24794

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM f…

No fix yet
Fix from $2,300 2024-02-20
Android HIGH 7.8
CVE-2023-21165

In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation…

Patch available
Fix from $1,950 2024-02-16
Android HIGH 7.8
CVE-2023-40107

In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with …

Patch available
Fix from $1,950 2024-02-15
Android HIGH 7.8
CVE-2023-40114

In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalation of p…

Patch available
Fix from $1,950 2024-02-15
Android HIGH 7.8
CVE-2023-40115

In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with…

Patch available
Fix from $1,950 2024-02-15
Android HIGH 7.8
CVE-2023-40100

In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of …

Patch available
Fix from $1,950 2024-02-15
Acrobat Dc HIGH 7.8
CVE-2024-20729

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code exe…

Fix: 20.005.30574 / 23.008.20533+
Fix from $1,950 2024-02-15
Acrobat Dc HIGH 7.8
CVE-2024-20731

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code exe…

Fix: 20.005.30574 / 23.008.20533+
Fix from $1,950 2024-02-15
Acrobat Dc MEDIUM 5.5
CVE-2024-20734

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensit…

Fix: 20.005.30574 / 23.008.20533+
Fix from $1,600 2024-02-15
FreeBSD HIGH 7.7
CVE-2022-23090

The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case. An attacker may cause th…

Mitigation only
Fix from $1,950 2024-02-15
Nginx Open Source HIGH 7.5
CVE-2024-24990

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note:…

Fix: 1.25.4+
Fix from $1,950 2024-02-14
365 Apps HIGH 7.8
CVE-2024-21384

Microsoft Office OneNote Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-02-13
Windows 10 1507 HIGH 8.8
CVE-2024-21375

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

Fix: 10.0.10240.20469 / 10.0.14393.6709+
Fix from $1,950 2024-02-13
Windows 10 1809 MEDIUM 6.4
CVE-2024-21339

Windows USB Generic Parent Driver Remote Code Execution Vulnerability

Fix: 10.0.17763.5458 / 10.0.19044.4046+
Fix from $1,600 2024-02-13
Azure Uamqp HIGH 8.1
CVE-2024-25110EPSS 7%

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-aft…

Fix: 2024-02-01+
Fix from $1,950 2024-02-12
Envoy HIGH 7.5
CVE-2024-23322

Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when …

Fix: 1.26.7 / 1.27.3+
Fix from $1,950 2024-02-09
Hugin HIGH 7.8
CVE-2024-25443

An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a …

No fix yet
Fix from $1,950 2024-02-09
Jsish CRITICAL 9.8
CVE-2024-24189

Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.

Mitigation only
Fix from $2,300 2024-02-07
Chrome CRITICAL 9.8
CVE-2024-1284

Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 121.0.6167.160+
Fix from $2,300 2024-02-07
Media Server HIGH 7.5
CVE-2024-24260

media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subscribe.c.

No fix yet
Fix from $1,950 2024-02-05
Media Server HIGH 7.5
CVE-2024-24262

media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transaction.c.

No fix yet
Fix from $1,950 2024-02-05
Lotos Webserver HIGH 7.5
CVE-2024-24263

Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/resp…

No fix yet
Fix from $1,950 2024-02-05
Gpac HIGH 7.5
CVE-2024-24266

gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.

No fix yet
Fix from $1,950 2024-02-05
Bifrost Gpu Kernel Driver HIGH 7.0
CVE-2023-5249

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make impro…

Mitigation only
Fix from $1,950 2024-02-05
Ghostscript CRITICAL 9.8
CVE-2020-36773

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single characte…

Patch available
Fix from $2,300 2024-02-04