Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Agatti Firmware HIGH 7.0
CVE-2020-11173

u'Two threads running simultaneously from user space can lead to race condition in fastRPC driver' in Snapdragon Auto, Snapdragon Compute, Snapdragon…

Patch available
Fix from $1,950 2020-11-02
Mac Os X HIGH 7.8
CVE-2020-3851

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave,…

Fix: 10.15.3 / 10.15.4+
Fix from $1,950 2020-10-27
Safari HIGH 8.8
CVE-2019-8846

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS …

Fix: 7.16 / 10.9+
Fix from $1,950 2020-10-27
Airport Base Station Firmware CRITICAL 9.8
CVE-2019-8578

A use after free issue was addressed with improved memory management. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base…

Fix: 7.8.1+
Fix from $2,300 2020-10-27
Iphone Os MEDIUM 6.7
CVE-2019-8528

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-…

Fix: 5.2 / 10.14.4+
Fix from $1,600 2020-10-27
Firefox CRITICAL 9.8
CVE-2020-15683

Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence o…

Fix: 78.4 / 82.0+
Fix from $2,300 2020-10-22
Firefox CRITICAL 9.8
CVE-2020-15684

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 82.0+
Fix from $2,300 2020-10-22
Fedora HIGH 7.0
CVE-2020-27672

An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly …

Fix: after 4.14.0
Fix from $1,950 2020-10-22
Cloud Foundation CRITICAL 9.8
CVE-2020-3992 KEVEPSS 83%

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after…

Fix: 3.10.1.2 / 4.1.0.1+
Fix from $2,300 2020-10-20
Mate 30 Firmware HIGH 7.8
CVE-2020-9263

HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10.1.0.160(C00E160R2P11) have a use after free vulne…

Fix: 10.1.0.150 / 10.1.0.160+
Fix from $1,950 2020-10-19
365 Apps HIGH 7.8
CVE-2020-16929

<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker…

Patch available
Fix from $1,950 2020-10-16
Safari HIGH 8.8
CVE-2020-9951

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content …

Fix: 7.0 / 11.5+
Fix from $1,950 2020-10-16
Safari HIGH 8.8
CVE-2020-9893

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Sa…

Fix: 6.2.8 / 7.20+
Fix from $1,950 2020-10-16
Safari CRITICAL 9.8
CVE-2020-9895

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Sa…

Fix: 6.2.8 / 7.20+
Fix from $2,300 2020-10-16
Bass MEDIUM 6.5
CVE-2019-18794

The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can…

Fix: after 2.4.14.1
Fix from $1,600 2020-10-16
Debian Linux HIGH 7.8
CVE-2020-0423

In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in t…

Mitigation only
Fix from $1,950 2020-10-14
Foxit Reader HIGH 7.8
CVE-2020-17417EPSS 9%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35811. User interaction is requ…

Fix: after 10.0.1.35811
Fix from $1,950 2020-10-13
Foxit Reader HIGH 7.8
CVE-2020-17410EPSS 9%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.0.35798. User interaction is …

Fix: after 10.0.1.35811
Fix from $1,950 2020-10-13
Virtual Gpu Manager HIGH 7.8
CVE-2020-5984

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which it may have the use-after-free vulnerability while freeing some resou…

Fix: 8.5 / 10.4+
Fix from $1,950 2020-10-02
Foxit Reader CRITICAL 9.8
CVE-2020-26534

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::Del…

Fix: 10.1+
Fix from $2,300 2020-10-02
Foxit Reader CRITICAL 9.8
CVE-2020-26539

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V (in the Additional Action an…

Fix: 10.1+
Fix from $2,300 2020-10-02
Firefox Esr HIGH 8.8
CVE-2020-15669

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-fr…

Fix: 68.12+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15670

Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we pres…

Fix: 78.2 / 80.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15673

Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption an…

Fix: 78.3 / 81.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15675

When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnera…

Fix: 81.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15678

When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs be…

Fix: 78.3 / 81.0+
Fix from $1,950 2020-10-01
Chrome CRITICAL 9.6
CVE-2020-6573

Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 85.0.4183.102+
Fix from $2,300 2020-09-21
Chrome HIGH 8.8
CVE-2020-6576

Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 85.0.4183.102+
Fix from $1,950 2020-09-21
Chrome HIGH 8.8
CVE-2020-6549EPSS 29%

Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 84.0.4147.125+
Fix from $1,950 2020-09-21
Chrome HIGH 8.8
CVE-2020-6550EPSS 29%

Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 84.0.4147.125+
Fix from $1,950 2020-09-21