Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 8.8
CVE-2022-0098

Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific use…

Fix: 97.0.4692.71+
Fix from $1,950 2022-02-12
Chrome HIGH 8.8
CVE-2022-0099

Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gestures to …

Fix: 97.0.4692.71+
Fix from $1,950 2022-02-12
Chrome HIGH 8.8
CVE-2022-0103

Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 97.0.4692.71+
Fix from $1,950 2022-02-12
Chrome HIGH 8.8
CVE-2022-0105

Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 97.0.4692.71+
Fix from $1,950 2022-02-12
Chrome HIGH 8.8
CVE-2022-0106

Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to …

Fix: 97.0.4692.71+
Fix from $1,950 2022-02-12
Chrome HIGH 8.8
CVE-2022-0107

Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a maliciou…

Fix: 97.0.4692.71+
Fix from $1,950 2022-02-12
Chrome HIGH 8.8
CVE-2021-4099

Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 96.0.4664.110+
Fix from $1,950 2022-02-11
Chrome HIGH 8.8
CVE-2021-4102 KEVEPSS 8%

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 96.0.4664.110+
Fix from $1,950 2022-02-11
Android HIGH 7.8
CVE-2021-39674

In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privile…

Patch available
Fix from $1,950 2022-02-11
Ar8035 Firmware HIGH 7.8
CVE-2021-35077

Possible use after free scenario in compute offloads to DSP while multiple calls spawn a dynamic process in Snapdragon Auto, Snapdragon Compute, Snap…

Patch available
Fix from $1,950 2022-02-11
Netweaver Application Server Java HIGH 7.5
CVE-2022-22533

Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53…

Mitigation only
Fix from $1,950 2022-02-09
Android HIGH 7.8
CVE-2022-20031

In fb driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional exec…

Mitigation only
Fix from $1,950 2022-02-09
Android HIGH 7.8
CVE-2022-20044

In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional executio…

Mitigation only
Fix from $1,950 2022-02-09
Android HIGH 7.8
CVE-2022-20045

In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional executio…

Mitigation only
Fix from $1,950 2022-02-09
Fedora HIGH 7.8
CVE-2022-0523

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

Fix: 5.6.2+
Fix from $1,950 2022-02-08
Fedora HIGH 7.8
CVE-2022-0520

Use After Free in NPM radare2.js prior to 5.6.2.

Fix: 5.6.2+
Fix from $1,950 2022-02-08
Radare2 CRITICAL 9.8
CVE-2022-0139

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

Fix: 5.6.0+
Fix from $2,300 2022-02-08
Tensorflow MEDIUM 6.5
CVE-2022-23584

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a use after free behavior when decoding PNG images. After `png::C…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Linux Kernel HIGH 8.8
CVE-2021-4154

A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a u…

Fix: 5.4.134 / 5.10.52+
Fix from $1,950 2022-02-04
Linux Kernel MEDIUM 5.5
CVE-2022-0487

A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this fl…

Fix: after 5.13.19
Fix from $1,600 2022-02-04
Pdf Reader HIGH 8.8
CVE-2021-40420

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document…

No fix yet
Fix from $1,950 2022-02-04
Fedora HIGH 7.8
CVE-2022-0443

Use After Free in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4281+
Fix from $1,950 2022-02-02
Desktop HIGH 8.8
CVE-2022-23597

Element Desktop is a Matrix client for desktop platforms with Element Web at its core. Element Desktop before 1.9.7 is vulnerable to a remote program…

Fix: 1.9.7+
Fix from $1,950 2022-02-01
MariaDB HIGH 7.5
CVE-2021-46669

MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.

Fix: 10.2.44 / 10.3.35+
Fix from $1,950 2022-02-01
Fedora HIGH 7.8
CVE-2022-0413

Use After Free in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4253+
Fix from $1,950 2022-01-30
Linux Kernel HIGH 7.8
CVE-2022-24122

kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalat…

Fix: 5.15.19 / 5.16.5+
Fix from $1,950 2022-01-29
Guicon HIGH 7.8
CVE-2021-22808

A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the…

Fix: after 2.0
Fix from $1,950 2022-01-28
Mjs HIGH 7.8
CVE-2021-46525

Cesanta MJS v2.20.0 was discovered to contain a heap-use-after-free via mjs_apply at src/mjs_exec.c.

Patch available
Fix from $1,950 2022-01-27
Jsish MEDIUM 5.5
CVE-2021-46499

Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueCopyMove in src/jsiValue.c. This vulnerability can lead to a Denial of Serv…

No fix yet
Fix from $1,600 2022-01-27
Jsish MEDIUM 5.5
CVE-2021-46500

Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ArgTypeCheck in src/jsiFunc.c. This vulnerability can lead to a Denial of Servic…

No fix yet
Fix from $1,600 2022-01-27