Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Debian Linux HIGH 7.8
CVE-2021-3516

There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trig…

Fix: 2.9.11+
Fix from $1,950 2021-06-01
Enterprise Linux MEDIUM 6.7
CVE-2021-3543

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descri…

Fix: 5.10.0+
Fix from $1,600 2021-06-01
Linux Kernel MEDIUM 6.7
CVE-2021-20292

There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau…

Fix: 4.9.298 / 4.14.263+
Fix from $1,600 2021-05-28
Qemu MEDIUM 6.7
CVE-2020-35506

A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the …

Fix: 6.0.0+
Fix from $1,600 2021-05-28
Fedora MEDIUM 5.5
CVE-2021-30469

A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.

Patch available
Fix from $1,600 2021-05-26
Linux Kernel HIGH 7.8
CVE-2020-25669

A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. T…

Fix: 4.4.245 / 4.9.245+
Fix from $1,950 2021-05-26
Linux Kernel HIGH 7.8
CVE-2020-25670

A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.

Fix: 4.4.267 / 4.9.267+
Fix from $1,950 2021-05-26
Linux Kernel HIGH 7.8
CVE-2020-25671

A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalati…

Fix: 4.4.267 / 4.9.267+
Fix from $1,950 2021-05-26
Fedora CRITICAL 9.8
CVE-2021-33574

The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes ob…

Fix: after 11.70.1
Fix from $2,300 2021-05-25
Bifrost Gpu Kernel Driver HIGH 8.8
CVE-2021-29256 KEV

. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege e…

Mitigation only
Fix from $1,950 2021-05-24
Enterprise Linux CRITICAL 9.8
CVE-2020-36329

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this…

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Fedora MEDIUM 5.5
CVE-2020-23856

Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via …

No fix yet
Fix from $1,600 2021-05-18
Debian Linux HIGH 8.8
CVE-2021-3518

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with l…

Fix: 2.9.11+
Fix from $1,950 2021-05-18
Linux Kernel HIGH 7.8
CVE-2021-3483

A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-…

Fix: 5.12+
Fix from $1,950 2021-05-17
Linux Kernel HIGH 7.8
CVE-2021-33033

The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DO…

Fix: 4.9.298 / 4.14.226+
Fix from $1,950 2021-05-14
Linux Kernel HIGH 7.8
CVE-2021-33034

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to wr…

Fix: 4.4.269 / 4.9.269+
Fix from $1,950 2021-05-14
Linux Kernel HIGH 7.8
CVE-2019-25044

The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege…

Patch available
Fix from $1,950 2021-05-14
Fedora MEDIUM 5.5
CVE-2021-32613

In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.

Fix: after 5.3.0
Fix from $1,600 2021-05-14
Linux Kernel HIGH 7.8
CVE-2021-23134

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configur…

Fix: 4.4.269 / 4.9.269+
Fix from $1,950 2021-05-12
Linux Kernel HIGH 7.8
CVE-2021-32606

In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (Thi…

Fix: 5.12.9+
Fix from $1,950 2021-05-11
Windows 10 HIGH 7.8
CVE-2021-31188

Windows Graphics Component Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-05-11
Windows 10 2004 CRITICAL 9.8
CVE-2021-31166 KEVEPSS 100%

HTTP Protocol Stack Remote Code Execution Vulnerability

Fix: 10.0.19041.982 / 10.0.19042.982+
Fix from $2,300 2021-05-11
Windows 10 HIGH 7.8
CVE-2021-31170

Windows Graphics Component Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-05-11
365 Apps HIGH 7.8
CVE-2021-31175

Microsoft Office Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-05-11
365 Apps HIGH 7.8
CVE-2021-31176

Microsoft Office Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-05-11
365 Apps HIGH 7.8
CVE-2021-31177

Microsoft Office Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-05-11
Foxit Reader HIGH 8.8
CVE-2021-21822

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A specially crafted PDF document…

No fix yet
Fix from $1,950 2021-05-10
Bifrost Gpu Kernel Driver HIGH 8.8
CVE-2021-28663 KEVEPSS 12%

The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-a…

Mitigation only
Fix from $1,950 2021-05-10
Phantompdf HIGH 7.8
CVE-2021-31458

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is requ…

Fix: after 10.1.37598
Fix from $1,950 2021-05-07
Phantompdf HIGH 7.8
CVE-2021-31459

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is requ…

Fix: after 10.1.3.37598
Fix from $1,950 2021-05-07