Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 8.8
CVE-2022-2742

Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage …

Fix: 104.0.5112.79+
Fix from $1,950 2023-01-02
Chrome HIGH 7.5
CVE-2022-3842EPSS 18%

Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 105.0.5195.125+
Fix from $1,950 2023-01-02
Chrome MEDIUM 6.1
CVE-2022-3863

Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 100.0.4896.75+
Fix from $1,600 2023-01-02
Gvariant Database HIGH 8.8
CVE-2019-25085

A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gv…

Fix: 2019-06-27+
Fix from $1,950 2022-12-26
Linux Kernel MEDIUM 5.5
CVE-2022-47946

An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to cras…

Fix: 5.10.155+
Fix from $1,600 2022-12-23
Linux Kernel CRITICAL 9.8
CVE-2022-47939EPSS 46%

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_…

Fix: 5.15.61 / 5.18.18+
Fix from $2,300 2022-12-23
Firefox MEDIUM 6.5
CVE-2022-46880

A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on De…

Fix: 102.6 / 105.0+
Fix from $1,600 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-46882

A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6…

Fix: 102.6 / 107.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-45406

If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a Base…

Fix: 102.5 / 107.0+
Fix from $2,300 2022-12-22
Firefox HIGH 7.5
CVE-2022-45407

If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exp…

Fix: 107.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-45409

The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, lead…

Fix: 102.5 / 107.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45405

Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable cr…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-40960

Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash…

Fix: 102.3 / 105.0+
Fix from $1,600 2022-12-22
Firefox Esr HIGH 7.5
CVE-2022-38476

A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock prot…

Fix: 102.2+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-34484

The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and…

Fix: 91.11 / 102.0+
Fix from $1,950 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-34470

Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR…

Fix: 91.11 / 102.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-31747

Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox …

Fix: 91.10 / 101+
Fix from $2,300 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-28282

By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution a…

Fix: 91.8 / 99.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-26485 KEVEPSS 14%

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing thi…

Fix: 91.6.1 / 91.6.2+
Fix from $1,950 2022-12-22
Firefox CRITICAL 9.6
CVE-2022-26486 KEV

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in th…

Fix: 91.6.1 / 91.6.2+
Fix from $2,300 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-26385

In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free causing a po…

Fix: 98.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-26381

An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerabili…

Fix: 91.7 / 98.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-22740

Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a pote…

Fix: 91.5 / 96.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-1097

<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use…

Fix: 91.8 / 99.0+
Fix from $1,600 2022-12-22
Firefox Esr MEDIUM 6.5
CVE-2022-1196

After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. Th…

Fix: 91.8+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2021-4128

When transitioning in and out of fullscreen mode, a graphics object was not correctly protected; resulting in memory corruption and a potentially exp…

Fix: 95.0+
Fix from $1,600 2022-12-22
Cx Drive HIGH 7.8
CVE-2022-46282

Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially cra…

Fix: after 3.00
Fix from $1,950 2022-12-21
Harmonyos HIGH 7.5
CVE-2022-46311

The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.

Fix: 2.0+
Fix from $1,950 2022-12-20
Fedora CRITICAL 9.8
CVE-2021-33640

After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use poin…

Mitigation only
Fix from $2,300 2022-12-19
Android MEDIUM 6.7
CVE-2022-42520

In ServiceInterface::HandleRequest of serviceinterface.cpp, there is a possible use after free. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,600 2022-12-16