Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome CRITICAL 9.6
CVE-2020-16018

Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially p…

Fix: 87.0.4280.66+
Fix from $2,300 2021-01-08
Firefox CRITICAL 9.8
CVE-2020-26972

The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a d…

Fix: 84.0+
Fix from $2,300 2021-01-07
Node.js HIGH 8.1
CVE-2020-8265EPSS 9%

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS ena…

Fix: 1.0.1.1 / 10.23.1+
Fix from $1,950 2021-01-06
Bitvec CRITICAL 9.8
CVE-2020-35862

An issue was discovered in the bitvec crate before 0.17.4 for Rust. BitVec to BitBox conversion leads to a use-after-free or double free.

Fix: 0.17.4+
Fix from $2,300 2020-12-31
Rusqlite CRITICAL 9.8
CVE-2020-35870

An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API use-after-free.

Fix: 0.23.0+
Fix from $2,300 2020-12-31
Rusqlite CRITICAL 9.8
CVE-2020-35873

An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because sessions.rs has a use-after-free.

Fix: 0.23.0+
Fix from $2,300 2020-12-31
Internment HIGH 8.1
CVE-2020-35874

An issue was discovered in the internment crate through 2020-05-28 for Rust. ArcIntern::drop has a race condition and resultant use-after-free.

Patch available
Fix from $1,950 2020-12-31
Rio CRITICAL 9.8
CVE-2020-35876

An issue was discovered in the rio crate through 2020-05-11 for Rust. A struct can be leaked, allowing attackers to obtain sensitive information, cau…

Fix: after 0.9.3
Fix from $2,300 2020-12-31
Libpulse Binding MEDIUM 6.5
CVE-2018-25001

An issue was discovered in the libpulse-binding crate before 2.5.0 for Rust. proplist::Iterator can cause a use-after-free.

Fix: 2.5.0+
Fix from $1,600 2020-12-31
Ordered Float MEDIUM 5.5
CVE-2020-35923

An issue was discovered in the ordered-float crate before 1.1.1 and 2.x before 2.0.1 for Rust. A NotNan value can contain a NaN.

Fix: 1.1.1 / 2.0.1+
Fix from $1,600 2020-12-31
Futures Task HIGH 7.8
CVE-2020-35906

An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situatio…

Fix: 0.3.6+
Fix from $1,950 2020-12-31
Pyo3 MEDIUM 5.5
CVE-2020-35917

An issue was discovered in the pyo3 crate before 0.12.4 for Rust. There is a reference-counting error and use-after-free in From<Py<T>>.

Fix: 0.12.4+
Fix from $1,600 2020-12-31
Actix Utils CRITICAL 9.1
CVE-2020-35898

An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more than one mutable reference to t…

Fix: 2.0.0+
Fix from $2,300 2020-12-31
Actix Service MEDIUM 5.5
CVE-2020-35899

An issue was discovered in the actix-service crate before 1.0.6 for Rust. The Cell implementation allows obtaining more than one mutable reference to…

Fix: 1.0.6+
Fix from $1,600 2020-12-31
Array Queue MEDIUM 5.5
CVE-2020-35900

An issue was discovered in the array-queue crate through 2020-09-26 for Rust. A pop_back() call may lead to a use-after-free.

Fix: after 2020-09-26
Fix from $1,600 2020-12-31
Actix Http HIGH 7.5
CVE-2020-35901

An issue was discovered in the actix-http crate before 2.0.0-alpha.1 for Rust. There is a use-after-free in BodyStream.

Fix: after 1.0.1
Fix from $1,950 2020-12-31
Actix Codec CRITICAL 9.8
CVE-2020-35902

An issue was discovered in the actix-codec crate before 0.3.0-beta.1 for Rust. There is a use-after-free in Framed.

Fix: after 0.2.0
Fix from $2,300 2020-12-31
Taurus Al00a Firmware MEDIUM 5.5
CVE-2020-9093

There is a use after free vulnerability in Taurus-AL00A versions 10.0.0.1(C00E1R1P1). A module does not deal with specific message properly, which ma…

Mitigation only
Fix from $1,600 2020-12-29
Foxit Reader HIGH 8.8
CVE-2020-13557EPSS 70%

A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF do…

No fix yet
Fix from $1,950 2020-12-22
Foxit Reader HIGH 8.8
CVE-2020-13560

A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF do…

No fix yet
Fix from $1,950 2020-12-22
Foxit Reader HIGH 8.8
CVE-2020-13570

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted PDF document…

No fix yet
Fix from $1,950 2020-12-22
Debian Linux MEDIUM 6.5
CVE-2020-29483

An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest viol…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Android MEDIUM 6.7
CVE-2020-27066

In xfrm6_tunnel_free_spi of net/ipv6/xfrm6_tunnel.c, there is a possible use after free due to improper locking. This could lead to local escalation …

Patch available
Fix from $1,600 2020-12-15
Android MEDIUM 6.4
CVE-2020-27067

In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execu…

Patch available
Fix from $1,600 2020-12-15
Linux Kernel HIGH 8.8
CVE-2020-29569

An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thr…

Fix: 4.2 / 4.4.254+
Fix from $1,950 2020-12-15
Android HIGH 7.8
CVE-2020-27044

In restartWrite of Parcel.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with n…

Patch available
Fix from $1,950 2020-12-15
Android MEDIUM 5.5
CVE-2020-27035

In priorLinearAllocation of C2AllocatorIon.cpp, there is a possible use-after-free due to improper locking. This could lead to local information disc…

Mitigation only
Fix from $1,600 2020-12-15
Android MEDIUM 5.5
CVE-2020-0496

In CPDF_RenderStatus::LoadSMask of cpdf_renderstatus.cpp, there is a possible memory corruption due to a use-after free. This could lead to local inf…

Mitigation only
Fix from $1,600 2020-12-15
Android HIGH 7.0
CVE-2020-0474

In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of pr…

Patch available
Fix from $1,950 2020-12-15
Android MEDIUM 6.7
CVE-2020-0483

In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corruption due to a use after free. This could lead t…

Patch available
Fix from $1,600 2020-12-15