Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Android MEDIUM 6.7
CVE-2020-0484

In destroyResources of ComposerClient.h, there is possible memory corruption due to a use after free. This could lead to local escalation of privileg…

Patch available
Fix from $1,600 2020-12-15
Android HIGH 7.8
CVE-2020-0466

In do_epoll_ctl and ep_loop_check_proc of eventpoll.c, there is a possible use after free due to a logic error. This could lead to local escalation o…

Patch available
Fix from $1,950 2020-12-14
Debian Linux HIGH 7.5
CVE-2020-8231

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

Fix: 1.0.1.1 / 8.2.12+
Fix from $1,950 2020-12-14
Linux Kernel HIGH 7.8
CVE-2020-27786

A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to …

Fix: 4.4.224 / 4.9.224+
Fix from $1,950 2020-12-11
Fedora MEDIUM 5.5
CVE-2020-16592

A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm…

No fix yet
Fix from $1,600 2020-12-09
Mupdf HIGH 7.8
CVE-2020-16600

A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with in…

Fix: after 1.16.1
Fix from $1,950 2020-12-09
Linux Kernel HIGH 7.8
CVE-2020-29661

A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack agai…

Fix: 4.4.248 / 4.9.248+
Fix from $1,950 2020-12-09
Firefox HIGH 8.8
CVE-2020-26959

During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, an…

Fix: 78.5 / 83.0+
Fix from $1,950 2020-12-09
Firefox HIGH 8.8
CVE-2020-26960

If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-…

Fix: 78.5 / 83.0+
Fix from $1,950 2020-12-09
Firefox HIGH 8.8
CVE-2020-26950EPSS 42%

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. Thi…

Fix: 78.4.1 / 78.4.2+
Fix from $1,950 2020-12-09
Safari HIGH 7.8
CVE-2020-27918

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 1…

Fix: 11.0.1 / 11.5+
Fix from $1,950 2020-12-08
Icloud HIGH 7.8
CVE-2020-27917

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 1…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2020-12-08
Ipados HIGH 7.8
CVE-2020-27926

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.2 and iPadOS 14.2. Processing maliciously crafted…

Fix: 14.2+
Fix from $1,950 2020-12-08
Imagemagick MEDIUM 5.5
CVE-2020-25663

A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or heap-buffer-ov…

Fix: 7.0.8-56+
Fix from $1,600 2020-12-08
Ipados HIGH 7.8
CVE-2020-9996

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malici…

Fix: 11.0.1 / 14.0+
Fix from $1,950 2020-12-08
Icloud HIGH 7.8
CVE-2020-9981

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Window…

Fix: 7.0 / 10.15.7+
Fix from $1,950 2020-12-08
Safari HIGH 8.8
CVE-2020-9947

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Window…

Fix: 7.0 / 11.5.0+
Fix from $1,950 2020-12-08
Ipados HIGH 7.8
CVE-2020-9949

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 1…

Fix: 7.0 / 10.15.6+
Fix from $1,950 2020-12-08
Safari HIGH 8.8
CVE-2020-9950

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, tvOS 14.0, Safari 14.0, iOS 14.0 and iPadOS…

Fix: 7.0 / 14.0+
Fix from $1,950 2020-12-08
Webkitgtk HIGH 8.8
CVE-2020-13543

A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after…

No fix yet
Fix from $1,950 2020-12-03
Fedora HIGH 8.8
CVE-2020-13584

An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-f…

No fix yet
Fix from $1,950 2020-12-03
Linux Kernel HIGH 7.8
CVE-2020-14351

A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monit…

Fix: 5.8.17+
Fix from $1,950 2020-12-03
Linux Kernel HIGH 7.8
CVE-2020-14381

A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges …

Fix: 5.6+
Fix from $1,950 2020-12-03
Openusd HIGH 8.8
CVE-2020-13531

A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specially crafted file can trigger …

No fix yet
Fix from $1,950 2020-12-03
Linux Kernel MEDIUM 5.3
CVE-2019-20934

An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because…

Fix: 4.19.64+
Fix from $1,600 2020-11-28
Sqlcipher HIGH 7.5
CVE-2020-27207

Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite3.c. A remote denial of servi…

Fix: 4.4.1+
Fix from $1,950 2020-11-26
Linux Kernel MEDIUM 6.7
CVE-2020-15436

Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by l…

Fix: 4.4.229 / 4.9.229+
Fix from $1,600 2020-11-23
Debian Linux HIGH 8.0
CVE-2019-14586

Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or d…

Mitigation only
Fix from $1,950 2020-11-23
MongoDB MEDIUM 6.5
CVE-2019-2393

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. T…

Fix: 3.6.15 / 4.0.13+
Fix from $1,600 2020-11-23
Fedora MEDIUM 5.5
CVE-2020-25725

In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes a…

No fix yet
Fix from $1,600 2020-11-21