Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Kostac Plc Programming Software HIGH 7.8
CVE-2023-22424

Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. With…

Fix: after 1.6.9.0
Fix from $1,950 2023-03-06
Linux Kernel HIGH 7.8
CVE-2023-1118

A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device. A local user…

Fix: 4.14.308 / 4.19.276+
Fix from $1,950 2023-03-02
Webkitgtk HIGH 8.8
CVE-2023-25361

A use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

Fix: 2.36.8+
Fix from $1,950 2023-03-02
Webkitgtk HIGH 8.8
CVE-2023-25362

A use-after-free vulnerability in WebCore::RenderLayer::repaintBlockSelectionGaps in WebKitGTK before 2.36.8 allows attackers to execute code remotel…

Fix: 2.36.8+
Fix from $1,950 2023-03-02
Webkitgtk HIGH 8.8
CVE-2023-25363

A use-after-free vulnerability in WebCore::RenderLayer::updateDescendantDependentFlags in WebKitGTK before 2.36.8 allows attackers to execute code re…

Fix: 2.36.8+
Fix from $1,950 2023-03-02
Fedora HIGH 8.8
CVE-2023-25358

A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

Fix: 2.36.8+
Fix from $1,950 2023-03-02
Webkitgtk HIGH 8.8
CVE-2023-25360

A use-after-free vulnerability in WebCore::RenderLayer::renderer in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

Fix: 2.36.8+
Fix from $1,950 2023-03-02
Android HIGH 7.8
CVE-2023-20933

In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2023-02-28
Android HIGH 7.8
CVE-2023-20937

In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. This could lead to local escalat…

Patch available
Fix from $1,950 2023-02-28
Android HIGH 7.8
CVE-2023-20938

In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escal…

Patch available
Fix from $1,950 2023-02-28
Linux Kernel HIGH 7.8
CVE-2023-0461

There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability …

Fix: 4.14.303 / 4.19.270+
Fix from $1,950 2023-02-28
Ipados HIGH 7.8
CVE-2023-23514

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 16.3.1 an…

Fix: 13.2.1 / 16.3.1+
Fix from $1,950 2023-02-27
Safari HIGH 8.8
CVE-2022-42826

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. P…

Fix: 2.40.1 / 13.0+
Fix from $1,950 2023-02-27
macOS HIGH 7.8
CVE-2022-46712

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13. An app may be able to cause unexpected…

Fix: 13.0+
Fix from $1,950 2023-02-27
Linux Kernel HIGH 7.8
CVE-2023-26605

In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del_entry_valid.

Fix: 5.15.81 / 6.0.0+
Fix from $1,950 2023-02-26
Linux Kernel HIGH 7.8
CVE-2023-26606

In the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c.

Fix: 5.15.86 / 6.0.16+
Fix from $1,950 2023-02-26
Linux Kernel HIGH 7.8
CVE-2023-26544

In the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sector size and media sect…

Fix: 5.15.87 / 6.0.17+
Fix from $1,950 2023-02-25
Chrome HIGH 8.8
CVE-2023-0927

Use after free in Web Payments API in Google Chrome on Android prior to 110.0.5481.177 allowed a remote attacker who had compromised the renderer pro…

Fix: 110.0.5481.177+
Fix from $1,950 2023-02-22
Chrome HIGH 8.8
CVE-2023-0928

Use after free in SwiftShader in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 110.0.5481.177+
Fix from $1,950 2023-02-22
Chrome HIGH 8.8
CVE-2023-0929

Use after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 110.0.5481.177+
Fix from $1,950 2023-02-22
Chrome HIGH 8.8
CVE-2023-0931

Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 110.0.5481.177+
Fix from $1,950 2023-02-22
Chrome HIGH 8.8
CVE-2023-0932

Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific U…

Fix: 110.0.5481.177+
Fix from $1,950 2023-02-22
Chrome HIGH 8.8
CVE-2023-0941

Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 110.0.5481.177+
Fix from $1,950 2023-02-22
Glusterfs HIGH 7.5
CVE-2022-48340

In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.

Patch available
Fix from $1,950 2023-02-21
Premiere Rush HIGH 7.8
CVE-2023-22244

Adobe Premiere Rush version 2.6 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the cont…

Fix: after 2.6
Fix from $1,950 2023-02-17
Animate HIGH 7.8
CVE-2023-22246

Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary co…

Fix: after 22.0.8
Fix from $1,950 2023-02-17
Framemaker MEDIUM 5.5
CVE-2023-21584

FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive …

Fix: after 2020.0.4
Fix from $1,600 2023-02-17
Tidy CRITICAL 9.8
CVE-2021-33391

An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.

Patch available
Fix from $2,300 2023-02-17
Linux Kernel MEDIUM 5.5
CVE-2023-23586

Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process. timens_install calls current_…

Fix: 5.10.161+
Fix from $1,600 2023-02-17
Xeon Gold 5315y Firmware MEDIUM 6.7
CVE-2022-30539

Use after free in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local …

Mitigation only
Fix from $1,600 2023-02-16