Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Android MEDIUM 6.7
CVE-2022-20581

In the Pixel camera driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,600 2022-12-16
Android HIGH 7.8
CVE-2022-20561

In TBD of aud_hal_tunnel.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no a…

Mitigation only
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20566

In l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no…

Patch available
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20568

In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no…

Patch available
Fix from $1,950 2022-12-16
Android MEDIUM 6.7
CVE-2022-20571

In extract_metadata of dm-android-verity.c, there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escala…

Patch available
Fix from $1,600 2022-12-16
Android HIGH 7.8
CVE-2022-20540

In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalat…

Patch available
Fix from $1,950 2022-12-16
Android MEDIUM 5.5
CVE-2022-20552

In btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to a use after free. This could lead to local inform…

Patch available
Fix from $1,600 2022-12-16
Android MEDIUM 6.7
CVE-2022-20554

In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege wi…

Patch available
Fix from $1,600 2022-12-16
Android MEDIUM 6.7
CVE-2022-20514

In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possible out o…

Patch available
Fix from $1,600 2022-12-16
Android HIGH 7.8
CVE-2022-20524

In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege wi…

Patch available
Fix from $1,950 2022-12-16
Safari HIGH 8.8
CVE-2022-42867EPSS 35%

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and…

Fix: 9.2 / 13.1+
Fix from $1,950 2022-12-15
Fedora HIGH 7.8
CVE-2022-4283

A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in…

Mitigation only
Fix from $1,950 2022-12-14
Fedora HIGH 8.8
CVE-2022-46342

A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it …

Mitigation only
Fix from $1,950 2022-12-14
Fedora HIGH 8.8
CVE-2022-46343

A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after …

Mitigation only
Fix from $1,950 2022-12-14
Chrome HIGH 8.8
CVE-2022-4437

Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 108.0.5359.124+
Fix from $1,950 2022-12-14
Chrome HIGH 8.8
CVE-2022-4438

Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI int…

Fix: 108.0.5359.124+
Fix from $1,950 2022-12-14
Chrome HIGH 8.8
CVE-2022-4439

Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI …

Fix: 108.0.5359.124+
Fix from $1,950 2022-12-14
Chrome HIGH 8.8
CVE-2022-4440

Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 108.0.5359.124+
Fix from $1,950 2022-12-14
Chrome HIGH 8.8
CVE-2022-4436

Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 108.0.5359.124+
Fix from $1,950 2022-12-14
Windows 10 HIGH 7.8
CVE-2022-44683EPSS 8%

Windows Kernel Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2022-12-13
Jt2go HIGH 7.8
CVE-2022-41285

A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visua…

Fix: 13.2.0.12 / 13.3.0.8+
Fix from $1,950 2022-12-13
Android MEDIUM 5.5
CVE-2022-20502

In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclos…

Patch available
Fix from $1,600 2022-12-13
Apq8096au Firmware HIGH 7.8
CVE-2022-25677

Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdrag…

Patch available
Fix from $1,950 2022-12-13
Android MEDIUM 5.5
CVE-2022-20496

In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local info…

Patch available
Fix from $1,600 2022-12-13
Valhall Gpu Kernel Driver HIGH 8.8
CVE-2022-42716

An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make improper GPU processing operatio…

No fix yet
Fix from $1,950 2022-12-12
Cx Programmer HIGH 7.8
CVE-2022-43508

Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by …

Fix: after 9.77
Fix from $1,950 2022-12-07
Android MEDIUM 5.5
CVE-2022-42754

In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-12-06
Connect Secure HIGH 7.5
CVE-2022-35254

An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R1…

Fix: 9.1+
Fix from $1,950 2022-12-05
Asterisk MEDIUM 6.5
CVE-2022-42705

A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to …

Fix: 16.29.1 / 18.15.1+
Fix from $1,600 2022-12-05
Vim HIGH 7.8
CVE-2022-4292

Use After Free in GitHub repository vim/vim prior to 9.0.0882.

Fix: 9.0.0882+
Fix from $1,950 2022-12-05