Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Libxml2 HIGH 7.5
CVE-2024-25062

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expan…

Fix: 2.11.7 / 2.12.5+
Fix from $1,950 2024-02-04
Openharmony HIGH 8.8
CVE-2024-21860

in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

Fix: after 3.2.4
Fix from $1,950 2024-02-02
Edge Chromium HIGH 8.3
CVE-2024-21399

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 121.0.2277.98+
Fix from $1,950 2024-02-02
Linux Kernel HIGH 7.8
CVE-2024-1085

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_…

Fix: 5.15.148 / 6.1.75+
Fix from $1,950 2024-01-31
Linux Kernel HIGH 7.8
CVE-2024-1086 KEVEPSS 28%

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nf…

Fix: 5.15.149 / 6.1.76+
Fix from $1,950 2024-01-31
Chrome HIGH 8.8
CVE-2024-1060

Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 121.0.6167.139+
Fix from $1,950 2024-01-30
Chrome HIGH 8.8
CVE-2024-1077

Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious f…

Fix: 121.0.6167.139+
Fix from $1,950 2024-01-30
Chrome HIGH 8.8
CVE-2024-1059

Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a cr…

Fix: 121.0.6167.139+
Fix from $1,950 2024-01-30
Linux Kernel HIGH 7.8
CVE-2024-21803

Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability i…

Fix: after 6.6.8
Fix from $1,950 2024-01-30
Edge Chromium CRITICAL 9.6
CVE-2024-21326

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 121.0.2277.83+
Fix from $2,300 2024-01-26
Edge Chromium HIGH 8.3
CVE-2024-21385

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 121.0.2277.83+
Fix from $1,950 2024-01-26
Chrome HIGH 8.8
CVE-2024-0813

Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to p…

Fix: 121.0.6167.85+
Fix from $1,950 2024-01-24
Chrome HIGH 8.8
CVE-2024-0806

Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI …

Fix: 121.0.6167.85+
Fix from $1,950 2024-01-24
Chrome HIGH 8.8
CVE-2024-0807

Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 121.0.6167.85+
Fix from $1,950 2024-01-24
Firefox MEDIUM 6.5
CVE-2024-0746

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, …

Fix: 115.7 / 122.0+
Fix from $1,600 2024-01-23
Firefox MEDIUM 6.5
CVE-2024-0752

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an expl…

Fix: 122.0+
Fix from $1,600 2024-01-23
Linux Kernel HIGH 7.8
CVE-2023-51042

In the Linux kernel before 6.4.12, amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free.

Fix: 6.4.12+
Fix from $1,950 2024-01-23
Linux Kernel HIGH 7.0
CVE-2023-51043

In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a…

Fix: 6.4.5+
Fix from $1,950 2024-01-23
Linux Kernel MEDIUM 5.5
CVE-2024-23848

In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/…

Fix: after 6.7.1
Fix from $1,600 2024-01-23
Linux Kernel HIGH 7.1
CVE-2024-0775

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an infor…

Fix: 6.4+
Fix from $1,950 2024-01-22
Swftools HIGH 7.8
CVE-2024-22956

swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838

No fix yet
Fix from $1,950 2024-01-19
Swftools MEDIUM 5.5
CVE-2024-22914

A heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620. It allows an attacker to cause denial of service.

No fix yet
Fix from $1,600 2024-01-19
Swftools HIGH 7.8
CVE-2024-22915

A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution.

No fix yet
Fix from $1,950 2024-01-19
Swftools HIGH 7.8
CVE-2024-22920

swftools 0.9.2 was discovered to contain a heap-use-after-free via the function bufferWriteData in swftools/lib/action/compile.c.

No fix yet
Fix from $1,950 2024-01-19
Openjdk HIGH 7.4
CVE-2024-20952

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp…

Fix: 11.0.24 / 17.0.10+
Fix from $1,950 2024-01-16
Linux Kernel HIGH 7.8
CVE-2024-0582EPSS 13%

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap(…

Fix: 6.6.5+
Fix from $1,950 2024-01-16
SQLite MEDIUM 5.5
CVE-2024-0232

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to …

Fix: 3.43.2+
Fix from $1,600 2024-01-16
Harmonyos HIGH 7.5
CVE-2023-52115

The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.

No fix yet
Fix from $1,950 2024-01-16
Linux Kernel HIGH 7.8
CVE-2024-0562

A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associ…

Fix: 5.15.164 / 5.19.6+
Fix from $1,950 2024-01-15
Live555 CRITICAL 9.8
CVE-2023-37117

A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.

No fix yet
Fix from $2,300 2024-01-12