Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Apq8009 Firmware HIGH 7.0
CVE-2020-11290

Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Sna…

Mitigation only
Fix from $1,950 2021-03-17
Apq8009 Firmware HIGH 7.8
CVE-2020-11309

Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, Snapdragon Co…

Patch available
Fix from $1,950 2021-03-17
Chrome HIGH 8.8
CVE-2021-21193 KEVEPSS 10%

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 89.0.4389.90+
Fix from $1,950 2021-03-16
Chrome HIGH 8.8
CVE-2021-21191

Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 89.0.4389.90+
Fix from $1,950 2021-03-16
Enterprise Linux CRITICAL 9.8
CVE-2021-20231

A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.

Fix: 3.7.1+
Fix from $2,300 2021-03-12
Enterprise Linux CRITICAL 9.8
CVE-2021-20232

A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potentia…

Fix: 3.7.1+
Fix from $2,300 2021-03-12
Diesel CRITICAL 9.8
CVE-2021-28305

An issue was discovered in the diesel crate before 1.4.6 for Rust. There is a use-after-free in the SQLite backend because the semantics of sqlite3_c…

Fix: 1.4.6+
Fix from $2,300 2021-03-12
Diskstation Manager CRITICAL 9.8
CVE-2021-27646

Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execut…

Fix: 6.2.3-25426-3+
Fix from $2,300 2021-03-12
Windows 10 HIGH 7.8
CVE-2021-26900

Windows Win32k Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-03-11
Edge HIGH 8.8
CVE-2021-26411 KEVEPSS 81%

Internet Explorer Memory Corruption Vulnerability

Patch available
Fix from $1,950 2021-03-11
Hhvm CRITICAL 9.8
CVE-2020-1900

When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything …

Fix: 4.32.3 / 4.56.1+
Fix from $2,300 2021-03-11
Fedora HIGH 8.1
CVE-2021-21772

A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3…

No fix yet
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0395

In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0399

In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,950 2021-03-10
Chrome HIGH 8.8
CVE-2021-21179

Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption …

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21180

Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21188

Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21167

Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21159

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21162

Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Enterprise Linux HIGH 7.8
CVE-2021-3403

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) …

No fix yet
Fix from $1,950 2021-03-04
Webkitgtk HIGH 8.8
CVE-2020-13558

A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can …

No fix yet
Fix from $1,950 2021-03-03
Fvdesigner HIGH 7.8
CVE-2021-22662

A use after free issue has been identified in Fatek FvDesigner Version 1.5.76 and prior in the way the application processes project files, allowing …

Fix: after 1.5.76
Fix from $1,950 2021-03-03
Enterprise Linux HIGH 8.2
CVE-2020-25632

A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking …

Fix: 2.06+
Fix from $1,950 2021-03-03
365 Apps HIGH 7.8
CVE-2021-24067

Microsoft Excel Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-02-25
365 Apps HIGH 7.8
CVE-2021-24070

Microsoft Excel Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-02-25
Linux Kernel HIGH 7.8
CVE-2021-20226

A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem…

Fix: 5.8.18 / 5.9.3+
Fix from $1,950 2021-02-23
Chrome CRITICAL 9.6
CVE-2021-21150

Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to …

Fix: 88.0.4324.182+
Fix from $2,300 2021-02-22
Chrome CRITICAL 9.6
CVE-2021-21151

Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HT…

Fix: 88.0.4324.182+
Fix from $2,300 2021-02-22
Fedora HIGH 8.8
CVE-2021-21157EPSS 9%

Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 88.0.705.74 / 88.0.4324.182+
Fix from $1,950 2021-02-22