Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Pdf2json MEDIUM 5.5
CVE-2020-19474

An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After Free .

Patch available
Fix from $1,600 2021-07-21
Linux Kernel MEDIUM 6.4
CVE-2021-37159

hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED st…

Fix: after 5.13.4
Fix from $1,600 2021-07-21
Openvswitch MEDIUM 5.5
CVE-2021-36980

Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) du…

Fix: after 2.15.0
Fix from $1,600 2021-07-20
Fedora MEDIUM 6.5
CVE-2021-36976

libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

Fix: 8.2.12 / 8.5+
Fix from $1,600 2021-07-20
Windows 10 HIGH 7.8
CVE-2021-34498

Windows GDI Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-07-14
Android HIGH 7.8
CVE-2021-0587

In StreamOut::prepareForWriting of StreamOut.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalatio…

Mitigation only
Fix from $1,950 2021-07-14
Jt2go HIGH 7.8
CVE-2021-34330

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affect…

Fix: 13.2.0+
Fix from $1,950 2021-07-13
Jt2go HIGH 7.8
CVE-2021-34324

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affect…

Fix: 13.2.0+
Fix from $1,950 2021-07-13
Jt2go HIGH 7.8
CVE-2021-34298

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in a…

Fix: 13.2.0+
Fix from $1,950 2021-07-13
Jt2go HIGH 7.8
CVE-2021-34301

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in a…

Fix: 13.2.0+
Fix from $1,950 2021-07-13
Aqt1000 Firmware HIGH 7.8
CVE-2021-1940

Use after free can occur due to improper handling of response from firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdrag…

Patch available
Fix from $1,950 2021-07-13
Design Review HIGH 7.8
CVE-2021-27037

A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt to free an object that has a…

Mitigation only
Fix from $1,950 2021-07-09
Webkitgtk HIGH 8.8
CVE-2021-21806

An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page can cause a use-after-f…

No fix yet
Fix from $1,950 2021-07-08
Fedora HIGH 8.8
CVE-2021-21779

A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page ca…

No fix yet
Fix from $1,950 2021-07-08
Fedora HIGH 8.0
CVE-2021-21775

A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted…

No fix yet
Fix from $1,950 2021-07-07
Acrn HIGH 7.5
CVE-2021-36144

The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/pci/virtio/*.c.

Fix: 2.5+
Fix from $1,950 2021-07-02
Acrn HIGH 7.5
CVE-2021-36145

The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.

Fix: after 2.5
Fix from $1,950 2021-07-02
Chrome HIGH 8.8
CVE-2021-30557EPSS 12%

Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to pote…

Fix: 91.0.4472.114+
Fix from $1,950 2021-07-02
Chrome HIGH 8.8
CVE-2021-30554 KEVEPSS 7%

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 91.0.4472.114+
Fix from $1,950 2021-07-02
Chrome HIGH 8.8
CVE-2021-30555

Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potent…

Fix: 91.0.4472.114+
Fix from $1,950 2021-07-02
Chrome HIGH 8.8
CVE-2021-30556

Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 91.0.4472.114+
Fix from $1,950 2021-07-02
Tesseract Ocr HIGH 7.8
CVE-2021-36081

Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.

Patch available
Fix from $1,950 2021-07-01
Keystone Engine HIGH 7.8
CVE-2020-36405

Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken.

Patch available
Fix from $1,950 2021-07-01
Emui CRITICAL 9.8
CVE-2021-22348

There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause code to…

Mitigation only
Fix from $2,300 2021-06-30
Emui HIGH 7.5
CVE-2021-22350

There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the dev…

No fix yet
Fix from $1,950 2021-06-30
Emui HIGH 7.5
CVE-2021-22353

There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the ker…

Mitigation only
Fix from $1,950 2021-06-30
Binary Ninja HIGH 7.8
CVE-2021-31516

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vector 35 Binary Ninja 2.3.2660 (Build ID 88f343c3)…

Mitigation only
Fix from $1,950 2021-06-29
Bindiff HIGH 7.8
CVE-2021-22545

An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset. This can allow the attacker t…

Fix: 7.0+
Fix from $1,950 2021-06-29
Linux Kernel HIGH 7.8
CVE-2021-28691

Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and ter…

Fix: 5.12.2+
Fix from $1,950 2021-06-29
Acrobat Dc HIGH 8.8
CVE-2021-28562EPSS 5%

Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use…

Fix: after 21.001.20150
Fix from $1,950 2021-06-28