Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Gpac HIGH 7.8
CVE-2020-35980

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.

Patch available
Fix from $1,950 2021-04-21
Debian Linux HIGH 7.8
CVE-2021-3497

GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.

Fix: 1.18.4+
Fix from $1,950 2021-04-19
Fbx Review HIGH 7.8
CVE-2021-27031

A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to r…

Fix: after 1.5.0
Fix from $1,950 2021-04-19
365 Apps HIGH 7.8
CVE-2021-28454

Microsoft Excel Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-04-13
Android HIGH 7.8
CVE-2021-0442

In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a use after free. This could lead…

Patch available
Fix from $1,950 2021-04-13
Android HIGH 7.8
CVE-2021-0429

In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no add…

Patch available
Fix from $1,950 2021-04-13
Rust CRITICAL 9.8
CVE-2020-36318

In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition.…

Fix: 1.49.0+
Fix from $2,300 2021-04-11
Chrome HIGH 8.8
CVE-2021-21194

Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 89.0.4389.114+
Fix from $1,950 2021-04-09
Chrome HIGH 8.8
CVE-2021-21195

Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 89.0.4389.114+
Fix from $1,950 2021-04-09
Chrome HIGH 8.8
CVE-2021-21199

Use after free in Aura in Google Chrome on Linux prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potenti…

Fix: 89.0.4389.114+
Fix from $1,950 2021-04-09
FreeBSD MEDIUM 5.5
CVE-2021-29626

In FreeBSD 13.0-STABLE before n245117, 12.2-STABLE before r369551, 11.4-STABLE before r369559, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-R…

Fix: 11.4 / 12.2+
Fix from $1,600 2021-04-07
FreeBSD HIGH 7.8
CVE-2021-29627

In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters im…

Fix: 12.2+
Fix from $1,950 2021-04-07
Apq8009 Firmware HIGH 7.8
CVE-2020-11234

When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread resulting in a Use A…

Patch available
Fix from $1,950 2021-04-07
Linux Kernel HIGH 7.8
CVE-2020-36313

An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef…

Fix: 5.7+
Fix from $1,950 2021-04-07
Safari HIGH 8.8
CVE-2021-1788

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, S…

Fix: 10.14.6 / 10.15.7+
Fix from $1,950 2021-04-02
Ipados HIGH 7.5
CVE-2021-1764

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, S…

Fix: 7.3 / 10.14.6+
Fix from $1,950 2021-04-02
Icloud HIGH 7.8
CVE-2020-9926

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, iC…

Fix: 6.2.8 / 7.20+
Fix from $1,950 2021-04-02
Ipados HIGH 7.8
CVE-2020-9975

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Sec…

Fix: 7.0 / 10.14.6+
Fix from $1,950 2021-04-02
Ipados HIGH 7.8
CVE-2020-27899

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS …

Fix: 7.1 / 11.0.1+
Fix from $1,950 2021-04-02
Mac Os X HIGH 8.8
CVE-2020-27920

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, S…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2021-04-02
Rocket HIGH 7.3
CVE-2021-29935

An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-provided function panics.

Fix: 0.4.7+
Fix from $1,950 2021-04-01
Foxit Reader HIGH 7.8
CVE-2021-27267

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is …

Fix: after 10.1.0.37527
Fix from $1,950 2021-03-30
Foxit Reader HIGH 7.8
CVE-2021-27268

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is …

Fix: after 10.1.0.37527
Fix from $1,950 2021-03-30
Linux Kernel HIGH 7.8
CVE-2021-29266

An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_ctx has an invalid value upon …

Fix: 5.10.26 / 5.11.9+
Fix from $1,950 2021-03-26
FreeBSD MEDIUM 5.5
CVE-2020-7462

In 11.4-PRERELEASE before r360733 and 11.3-RELEASE before p13, improper mbuf handling in the kernel causes a use-after-free bug by sending IPv6 Hop-b…

Mitigation only
Fix from $1,600 2021-03-26
FreeBSD MEDIUM 5.5
CVE-2020-7463

In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, impro…

Fix: 11.3 / 12.3+
Fix from $1,600 2021-03-26
Arcgis Server MEDIUM 6.8
CVE-2021-29093

A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with…

Fix: after 10.8.1
Fix from $1,600 2021-03-25
Arcgis Engine HIGH 7.8
CVE-2021-29096

A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS…

Fix: after 10.8.1
Fix from $1,950 2021-03-25
SQLite MEDIUM 5.5
CVE-2021-20227

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on…

Fix: 3.34.1 / 9.2.6.0+
Fix from $1,600 2021-03-23
Nip6300 Firmware MEDIUM 5.3
CVE-2021-22321

There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploi…

Mitigation only
Fix from $1,600 2021-03-22