Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Apq8096au Firmware HIGH 7.8
CVE-2020-11120

u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the callback, data buffer may no…

Mitigation only
Fix from $1,950 2020-09-08
Bitra Firmware HIGH 7.8
CVE-2019-14117

u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from the list which results in a us…

Patch available
Fix from $1,950 2020-09-08
Enterprise Linux MEDIUM 5.5
CVE-2020-14373

A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to …

Patch available
Fix from $1,600 2020-09-03
Linux Kernel MEDIUM 5.5
CVE-2020-10720

A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the syst…

Fix: 5.2+
Fix from $1,600 2020-09-03
Inspiron 7347 Bios MEDIUM 6.8
CVE-2020-5376

Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memor…

Mitigation only
Fix from $1,600 2020-09-02
G7 17 7790 Bios MEDIUM 6.8
CVE-2020-5378

Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memor…

Fix: 1.13.2+
Fix from $1,600 2020-09-02
Bison MEDIUM 5.5
CVE-2020-24240

GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is …

Patch available
Fix from $1,600 2020-08-25
Netwide Assembler MEDIUM 5.5
CVE-2020-24241

In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.

No fix yet
Fix from $1,600 2020-08-25
Acrobat Dc HIGH 7.8
CVE-2020-9722EPSS 6%

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-…

Fix: after 20.009.20074
Fix from $1,950 2020-08-19
Acrobat Dc HIGH 7.8
CVE-2020-9715 KEVEPSS 48%

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-…

Fix: after 20.009.20074
Fix from $1,950 2020-08-19
Taurus Al00b Firmware MEDIUM 6.7
CVE-2020-9237

Huawei smartphone Taurus-AL00B with versions earlier than 10.1.0.126(C00E125R5P3) have a user after free vulnerability. A module is lack of lock prot…

Fix: 10.1.0.126+
Fix from $1,600 2020-08-17
Njs MEDIUM 5.5
CVE-2020-24349

njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff"…

Fix: after 0.4.3
Fix from $1,600 2020-08-13
Mujs HIGH 7.8
CVE-2020-24343

Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c.

Fix: after 1.0.7
Fix from $1,950 2020-08-13
Njs HIGH 7.8
CVE-2020-24346

njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.

Fix: after 0.4.3
Fix from $1,950 2020-08-13
Debian Linux HIGH 7.8
CVE-2020-16303

A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker …

No fix yet
Fix from $1,950 2020-08-13
Android HIGH 7.8
CVE-2020-0242

In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the m…

Mitigation only
Fix from $1,950 2020-08-11
Android HIGH 7.8
CVE-2020-0243

In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privi…

Mitigation only
Fix from $1,950 2020-08-11
Android CRITICAL 9.8
CVE-2020-0252

There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152236803

Mitigation only
Fix from $2,300 2020-08-11
Android CRITICAL 9.8
CVE-2020-0253

There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152647365

No fix yet
Fix from $2,300 2020-08-11
Daviewindy HIGH 7.8
CVE-2020-7827

DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandle…

Fix: after 8.98.7
Fix from $1,950 2020-07-30
Saipan Firmware HIGH 7.8
CVE-2020-3701

Use after free issue while processing error notification from camx driver due to not properly releasing the sequence data in Snapdragon Mobile in Sai…

Mitigation only
Fix from $1,950 2020-07-30
Mdm9607 Firmware HIGH 7.8
CVE-2019-10580

When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been already freed in Snapdragon Au…

Patch available
Fix from $1,950 2020-07-30
Apq8009 Firmware HIGH 7.8
CVE-2019-14037

Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, S…

Patch available
Fix from $1,950 2020-07-30
Apq8009 Firmware CRITICAL 9.8
CVE-2020-3671

Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compute, Snapdragon Consumer IOT, …

Mitigation only
Fix from $2,300 2020-07-30
Enterprise Linux Atomic Host MEDIUM 6.4
CVE-2020-15706

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a fun…

Fix: after 2.04
Fix from $1,600 2020-07-29
Chrome CRITICAL 9.6
CVE-2020-6509

Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to pot…

Fix: 83.0.4103.116+
Fix from $2,300 2020-07-22
Chrome HIGH 8.8
CVE-2020-6515

Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6518

Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools …

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Chrome CRITICAL 9.6
CVE-2020-6505

Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML…

Fix: 83.0.4103.106+
Fix from $2,300 2020-07-22
Lua HIGH 8.8
CVE-2020-15888

Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer…

Patch available
Fix from $1,950 2020-07-21