Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Fedora MEDIUM 5.3
CVE-2021-42779

A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.

Fix: 0.22.0+
Fix from $1,600 2022-04-18
Gt.m HIGH 7.5
CVE-2021-44497

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, can cause the bounds of a for loop to b…

Fix: after 7.0-000
Fix from $1,950 2022-04-15
Fedora HIGH 8.8
CVE-2022-28042

stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.

Patch available
Fix from $1,950 2022-04-15
Njs CRITICAL 9.8
CVE-2022-27007

nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_func…

Patch available
Fix from $2,300 2022-04-14
MariaDB HIGH 7.5
CVE-2022-27455

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.

Fix: 10.4.25 / 10.5.16+
Fix from $1,950 2022-04-14
MariaDB HIGH 7.5
CVE-2022-27456

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.

Fix: 10.3.35 / 10.4.25+
Fix from $1,950 2022-04-14
MariaDB HIGH 7.5
CVE-2022-27457

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.

Fix: 10.4.25 / 10.5.16+
Fix from $1,950 2022-04-14
MariaDB HIGH 7.5
CVE-2022-27447

MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.

Fix: 10.3.35 / 10.4.25+
Fix from $1,950 2022-04-14
Linux Kernel MEDIUM 6.3
CVE-2022-1280

A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows…

Fix: after 5.17.4
Fix from $1,600 2022-04-13
MariaDB HIGH 7.5
CVE-2022-27376

MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially c…

Fix: 10.3.35 / 10.4.25+
Fix from $1,950 2022-04-12
MariaDB HIGH 7.5
CVE-2022-27377

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via special…

Fix: 10.2.44 / 10.3.35+
Fix from $1,950 2022-04-12
MariaDB HIGH 7.5
CVE-2022-27383

MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially craf…

Fix: 10.2.44 / 10.3.35+
Fix from $1,950 2022-04-12
Subversion HIGH 7.5
CVE-2022-24070EPSS 9%

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use …

Fix: 1.10.8 / 1.14.2+
Fix from $1,950 2022-04-12
Android MEDIUM 5.5
CVE-2021-39800

In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosur…

Patch available
Fix from $1,600 2022-04-12
Android HIGH 7.8
CVE-2021-39801

In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no add…

Patch available
Fix from $1,950 2022-04-12
Android MEDIUM 6.5
CVE-2021-39803

In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with…

Patch available
Fix from $1,600 2022-04-12
Android HIGH 7.8
CVE-2021-39812

In TBD of TBD, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with no additional ex…

Patch available
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-0707

In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with…

Patch available
Fix from $1,950 2022-04-12
Android HIGH 7.0
CVE-2022-27834

Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious…

Mitigation only
Fix from $1,950 2022-04-11
Navisworks HIGH 7.8
CVE-2022-27528

A maliciously crafted DWFX and SKP files in Autodesk Navisworks 2022 can be used to trigger use-after-free vulnerability. Exploitation of this vulner…

Fix: 2022.2+
Fix from $1,950 2022-04-11
Advance Steel HIGH 7.8
CVE-2022-25789

A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploit…

Fix: 2019.1.4 / 2020.1.5+
Fix from $1,950 2022-04-11
Android MEDIUM 6.5
CVE-2022-20052

In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privile…

Mitigation only
Fix from $1,600 2022-04-11
Android MEDIUM 6.7
CVE-2022-20062

In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privile…

Mitigation only
Fix from $1,600 2022-04-11
Linux Kernel HIGH 7.8
CVE-2022-28893

The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.

Fix: 5.4.196 / 5.10.117+
Fix from $1,950 2022-04-11
Radare2 MEDIUM 5.5
CVE-2022-1284

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

Fix: 5.6.8+
Fix from $1,600 2022-04-08
Gpac MEDIUM 5.5
CVE-2022-27147

GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_tag.

Fix: 2.0.0+
Fix from $1,600 2022-04-08
Libsixel HIGH 8.8
CVE-2021-41715

libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.

No fix yet
Fix from $1,950 2022-04-08
Libsixel HIGH 8.8
CVE-2022-27046

libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.

No fix yet
Fix from $1,950 2022-04-08
Mruby CRITICAL 9.8
CVE-2022-1212

Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

Fix: after 3.0.0
Fix from $2,300 2022-04-05
Chrome HIGH 8.8
CVE-2022-0805

Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user i…

Fix: 99.0.4844.51+
Fix from $1,950 2022-04-05