Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Openharmony MEDIUM 5.5
CVE-2023-48360

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

Fix: after 3.2.2
Fix from $1,600 2024-01-02
Openharmony MEDIUM 5.5
CVE-2023-49135

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

Fix: after 3.2.2
Fix from $1,600 2024-01-02
Ar8035 Firmware HIGH 7.8
CVE-2023-43514

Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.

Patch available
Fix from $1,950 2024-01-02
315 5g Iot Modem Firmware HIGH 7.8
CVE-2023-33114

Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.

Patch available
Fix from $1,950 2024-01-02
Ar8035 Firmware HIGH 7.8
CVE-2023-33117

Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.

Patch available
Fix from $1,950 2024-01-02
Ar8035 Firmware HIGH 7.8
CVE-2023-33118

Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HA…

Patch available
Fix from $1,950 2024-01-02
315 5g Iot Modem Firmware HIGH 7.8
CVE-2023-33120

Memory corruption in Audio when memory map command is executed consecutively in ADSP.

Mitigation only
Fix from $1,950 2024-01-02
Ar8035 Firmware HIGH 7.8
CVE-2023-33094

Memory corruption while running VK synchronization with KASAN enabled.

No fix yet
Fix from $1,950 2024-01-02
Qam8255p Firmware HIGH 7.8
CVE-2023-33108

Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued.

Patch available
Fix from $1,950 2024-01-02
Ehttp HIGH 7.5
CVE-2023-52266

ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over a short time to trigger this.

Patch available
Fix from $1,950 2023-12-31
Micropython CRITICAL 9.8
CVE-2023-7152

A vulnerability, which was classified as critical, has been found in MicroPython 1.21.0/1.22.0-preview. Affected by this issue is the function poll_s…

Patch available
Fix from $2,300 2023-12-29
Debian Linux HIGH 7.0
CVE-2023-6932

A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition c…

Fix: 4.14.332 / 4.19.301+
Fix from $1,950 2023-12-19
Firefox HIGH 8.8
CVE-2023-6859

A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115…

Fix: 115.6 / 121.0+
Fix from $1,950 2023-12-19
Firefox Esr HIGH 8.8
CVE-2023-6862

A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firef…

Fix: 115.6+
Fix from $1,950 2023-12-19
Linux Kernel HIGH 7.8
CVE-2023-6817

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The func…

Fix: 5.10.204 / 5.15.143+
Fix from $1,950 2023-12-18
Chrome HIGH 8.8
CVE-2023-6703

Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 120.0.6099.109+
Fix from $1,950 2023-12-14
Chrome HIGH 8.8
CVE-2023-6704

Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted ima…

Fix: 120.0.6099.109+
Fix from $1,950 2023-12-14
Chrome HIGH 8.8
CVE-2023-6705

Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 120.0.6099.109+
Fix from $1,950 2023-12-14
Chrome HIGH 8.8
CVE-2023-6706

Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engage in specific UI interaction …

Fix: 120.0.6099.109+
Fix from $1,950 2023-12-14
Chrome HIGH 8.8
CVE-2023-6707

Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 120.0.6099.109+
Fix from $1,950 2023-12-14
After Effects HIGH 7.8
CVE-2023-48633

Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitr…

Fix: after 24.0.3
Fix from $1,950 2023-12-13
Illustrator HIGH 7.8
CVE-2023-47075

Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary co…

Fix: after 27.9
Fix from $1,950 2023-12-13
Photon Os HIGH 7.8
CVE-2022-22942

The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processe…

Mitigation only
Fix from $1,950 2023-12-13
Windows 10 1507 HIGH 8.1
CVE-2023-35628EPSS 93%

Windows MSHTML Platform Remote Code Execution Vulnerability

Fix: 10.0.10240.20345 / 10.0.14393.6529+
Fix from $1,950 2023-12-12
Simatic Drive Controller Cpu 1504d Tf Firmware HIGH 7.5
CVE-2023-46156

Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condit…

Fix: 3.1.0+
Fix from $1,950 2023-12-12
Android MEDIUM 6.7
CVE-2023-48414

In the Pixel Camera Driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,600 2023-12-08
Edge Chromium CRITICAL 9.6
CVE-2023-35618

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 120.0.2210.61+
Fix from $2,300 2023-12-07
Ghostscript HIGH 7.5
CVE-2023-46751

An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the …

Fix: after 10.02.0
Fix from $1,950 2023-12-06
Chrome HIGH 8.8
CVE-2023-6508

Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 120.0.6099.62+
Fix from $1,950 2023-12-06
Debian Linux HIGH 8.8
CVE-2023-6509

Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI i…

Fix: 120.0.6099.62+
Fix from $1,950 2023-12-06