Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Media Server HIGH 7.5
CVE-2022-40016

Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in librtmp, allows attackers to cau…

Fix: 2022-08-06+
Fix from $1,950 2023-02-15
.net HIGH 7.8
CVE-2023-21808

.NET and Visual Studio Remote Code Execution Vulnerability

Fix: 15.9.51 / 16.11.24+
Fix from $1,950 2023-02-14
Windows 10 HIGH 7.8
CVE-2023-21822

Windows Graphics Component Elevation of Privilege Vulnerability

Fix: 10.0.10240.19747 / 10.0.14393.5717+
Fix from $1,950 2023-02-14
Windows 10 1507 HIGH 7.8
CVE-2023-21688

NT OS Kernel Elevation of Privilege Vulnerability

Fix: 10.0.10240.19747 / 10.0.14393.5717+
Fix from $1,950 2023-02-14
Solid Edge Se2023 HIGH 7.8
CVE-2023-24581

A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versio…

Fix: 2210.0002.004+
Fix from $1,950 2023-02-14
Libtiff MEDIUM 5.5
CVE-2023-0799

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-service via a crafted tiff file…

Fix: after 4.4.0
Fix from $1,600 2023-02-13
Screen Creator Advance 2 HIGH 7.8
CVE-2023-22360

Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an er…

Fix: after 0.1.1.4
Fix from $1,950 2023-02-13
Android MEDIUM 5.5
CVE-2022-47371

In bt driver, there is a thread competition leads to early release of resources to be accessed. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2023-02-12
Apq8096au Firmware HIGH 7.8
CVE-2022-33225

Memory corruption due to use after free in trusted application environment.

Patch available
Fix from $1,950 2023-02-12
Curl MEDIUM 5.9
CVE-2022-43552

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP …

Fix: 7.87.0 / 8.2.12+
Fix from $1,600 2023-02-09
OpenSSL HIGH 7.5
CVE-2023-0215

The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to supp…

Fix: 1.0.2zg / 1.1.1t+
Fix from $1,950 2023-02-08
Chrome HIGH 8.8
CVE-2023-0699

Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 110.0.5481.77+
Fix from $1,950 2023-02-07
Android MEDIUM 6.4
CVE-2023-20608

In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution pr…

Mitigation only
Fix from $1,600 2023-02-06
Linux Kernel HIGH 7.8
CVE-2023-0240

There is a logic error in io_uring's implementation which can be used to trigger a use-after-free vulnerability leading to privilege escalation. In …

Fix: 5.10+
Fix from $1,950 2023-01-30
Debian Linux HIGH 7.0
CVE-2023-0266 KEV

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be u…

Fix: 4.14.303 / 4.19.270+
Fix from $1,950 2023-01-30
Chrome HIGH 8.8
CVE-2023-0471

Use after free in WebTransport in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 109.0.5414.119+
Fix from $1,950 2023-01-30
Chrome HIGH 8.8
CVE-2023-0472

Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 109.0.5414.119+
Fix from $1,950 2023-01-30
Chrome HIGH 8.8
CVE-2023-0474

Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install a malicious extension to pot…

Fix: 109.0.5414.119+
Fix from $1,950 2023-01-30
Android HIGH 7.8
CVE-2023-20920

In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2023-20925

In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalat…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2023-20928

In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no…

No fix yet
Fix from $1,950 2023-01-26
Linux Kernel MEDIUM 5.5
CVE-2023-0469

A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup…

Fix: 6.1+
Fix from $1,600 2023-01-26
Bind HIGH 7.5
CVE-2022-3094EPSS 13%

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack …

Fix: 9.16.37 / 9.18.11+
Fix from $1,950 2023-01-26
Pdf Xchange Editor MEDIUM 5.5
CVE-2022-42414

This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is req…

Fix: 9.5.366.0+
Fix from $1,600 2023-01-26
Pdf Xchange Editor MEDIUM 5.5
CVE-2022-42408

This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is req…

Fix: 9.5.366.0+
Fix from $1,600 2023-01-26
Pdf Xchange Editor HIGH 7.8
CVE-2022-42374

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to…

Fix: 9.5.366.0+
Fix from $1,950 2023-01-26
Edge Chromium HIGH 8.3
CVE-2023-21795

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 109.0.1518.70+
Fix from $1,950 2023-01-24
Byacc HIGH 7.8
CVE-2021-33641

When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use aft…

Fix: 1.9.20200330 / 2.0.20210808+
Fix from $1,950 2023-01-20
Assimp HIGH 8.8
CVE-2022-45748

An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file /code/AssetLib/C…

No fix yet
Fix from $1,950 2023-01-20
Acrobat Dc HIGH 7.8
CVE-2023-21608 KEVEPSS 61%

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free …

Fix: after 22.003.20282
Fix from $1,950 2023-01-18