Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Gpac MEDIUM 5.5
CVE-2021-45262

An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault and application crash.

No fix yet
Fix from $1,600 2021-12-22
Gpac MEDIUM 5.5
CVE-2021-45263

An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmentation fault and application …

No fix yet
Fix from $1,600 2021-12-22
Gpac MEDIUM 5.5
CVE-2021-45291

The gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a denial of service (Invalid memory address dereference) via a crafted file …

No fix yet
Fix from $1,600 2021-12-21
Android MEDIUM 6.7
CVE-2021-0893

In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution priv…

Mitigation only
Fix from $1,600 2021-12-17
Android MEDIUM 6.7
CVE-2021-0898

In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution priv…

Mitigation only
Fix from $1,600 2021-12-17
Android MEDIUM 6.7
CVE-2021-0899

In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution priv…

Mitigation only
Fix from $1,600 2021-12-17
Android MEDIUM 6.7
CVE-2021-39638

In periodic_io_work_func of lwis_periodic_io.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation …

Patch available
Fix from $1,600 2021-12-15
Android MEDIUM 6.7
CVE-2021-39656

In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in th…

Patch available
Fix from $1,600 2021-12-15
Android HIGH 7.8
CVE-2021-1028

In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation o…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-1029

In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation o…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-1048 KEV

In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privi…

Patch available
Fix from $1,950 2021-12-15
Linux Kernel MEDIUM 6.4
CVE-2021-0920 KEV

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege wit…

Fix: after 5.13
Fix from $1,600 2021-12-15
Android HIGH 7.8
CVE-2021-0929

In ion_dma_buf_end_cpu_access and related functions of ion.c, there is a possible way to corrupt memory due to a use after free. This could lead to l…

Mitigation only
Fix from $1,950 2021-12-15
Jt Open Toolkit HIGH 7.8
CVE-2021-44433

A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products co…

Fix: 11.1.1.0 / 13.1.1.0+
Fix from $1,950 2021-12-14
Jt Open Toolkit HIGH 7.8
CVE-2021-44447

A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products co…

Fix: 11.0.3.0 / 13.0.3.0+
Fix from $1,950 2021-12-14
Jt Open Toolkit HIGH 7.8
CVE-2021-44014

A vulnerability has been identified in JT Open (All versions < V11.1.1.0), JT Utilities (All versions < V13.1.1.0), Solid Edge (All versions < V2023)…

Fix: 11.1.1.0 / 13.1.1.0+
Fix from $1,950 2021-12-14
Firefox HIGH 8.8
CVE-2021-43535

A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially e…

Fix: 91.3.0 / 93.0+
Fix from $1,950 2021-12-08
Firefox HIGH 8.8
CVE-2021-43539

Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those liv…

Fix: 91.4.0 / 95.0+
Fix from $1,950 2021-12-08
Firefox HIGH 8.8
CVE-2021-38504

When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory co…

Fix: 91.3.0 / 94.0+
Fix from $1,950 2021-12-08
Harmonyos CRITICAL 9.8
CVE-2021-37045

There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart unexpectedly and the…

Fix: 2.0+
Fix from $2,300 2021-12-08
Fedora HIGH 7.8
CVE-2021-4069

vim is vulnerable to Use After Free

Fix: 8.2.3741+
Fix from $1,950 2021-12-06
Drawings Sdk HIGH 7.8
CVE-2021-44047

A use-after-free vulnerability exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists …

Fix: 2022.11+
Fix from $1,950 2021-12-05
Lucet HIGH 8.1
CVE-2021-43790

Lucet is a native WebAssembly compiler and runtime. There is a bug in the main branch of `lucet-runtime` affecting all versions published to crates.i…

Fix: after 0.6.1
Fix from $1,950 2021-11-30
Chrome HIGH 8.8
CVE-2021-37997

Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially ex…

Fix: 95.0.4638.69+
Fix from $1,950 2021-11-23
Chrome HIGH 8.8
CVE-2021-37998

Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 95.0.4638.69+
Fix from $1,950 2021-11-23
Chrome CRITICAL 9.6
CVE-2021-38002

Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafte…

Fix: 95.0.4638.69+
Fix from $2,300 2021-11-23
Drawings Sdk HIGH 7.8
CVE-2021-43582

A Use-After-Free Remote Vulnerability exists when reading a DWG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exist…

Fix: 2022.11+
Fix from $1,950 2021-11-22
Debian Linux HIGH 8.8
CVE-2021-21900

A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dx…

No fix yet
Fix from $1,950 2021-11-19
Imagemagick HIGH 7.8
CVE-2021-3962EPSS 6%

A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an att…

Patch available
Fix from $1,950 2021-11-19
Fedora HIGH 7.8
CVE-2021-3974

vim is vulnerable to Use After Free

Fix: 8.2.3612+
Fix from $1,950 2021-11-19