Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
365 Apps HIGH 8.8
CVE-2020-1225EPSS 17%

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft…

Patch available
Fix from $1,950 2020-06-09
365 Apps HIGH 8.8
CVE-2020-1226EPSS 17%

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft…

Patch available
Fix from $1,950 2020-06-09
Windows 10 HIGH 7.8
CVE-2020-1207

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k…

Patch available
Fix from $1,950 2020-06-09
Ipados HIGH 7.8
CVE-2020-9795

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 1…

Fix: 6.2.5 / 10.15.5+
Fix from $1,950 2020-06-09
Ubuntu Linux MEDIUM 5.5
CVE-2020-13904

FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, …

Patch available
Fix from $1,600 2020-06-07
SQLite HIGH 7.5
CVE-2020-13871

SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.

Fix: after 8.0.22
Fix from $1,950 2020-06-06
Phantompdf CRITICAL 9.8
CVE-2020-13814

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary.

Fix: 9.7.1+
Fix from $2,300 2020-06-04
Phantompdf HIGH 7.5
CVE-2020-13806

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execution after a deletion or clos…

Fix: 9.7.2+
Fix from $1,950 2020-06-04
Chrome CRITICAL 9.6
CVE-2020-6493

Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 83.0.4103.97+
Fix from $2,300 2020-06-03
Chrome HIGH 8.8
CVE-2020-6496

Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a cr…

Fix: 83.0.4103.97+
Fix from $1,950 2020-06-03
Qca8081 Firmware HIGH 7.8
CVE-2020-3618

NULL exception due to accessing bad pointer while posting events on RT FIFO in Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure…

Mitigation only
Fix from $1,950 2020-06-02
Msm8909w Firmware HIGH 7.8
CVE-2019-14087

Failure in buffer management while accessing handle for HDR blit when color modes not supported by display in Snapdragon Consumer IOT, Snapdragon Mob…

Patch available
Fix from $1,950 2020-06-02
SQLite HIGH 7.0
CVE-2020-13630

ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

Fix: 3.32.0+
Fix from $1,950 2020-05-27
Firefox HIGH 8.1
CVE-2020-12387

A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. T…

Fix: 68.8.0 / 76.0+
Fix from $1,950 2020-05-26
E6878 370 Firmware HIGH 7.5
CVE-2020-1799

E6878-370 with versions of 10.0.3.1(H557SP27C233), 10.0.3.1(H563SP1C00), 10.0.3.1(H563SP1C233) has a use after free vulnerability. The software refer…

Mitigation only
Fix from $1,950 2020-05-21
Chrome HIGH 8.8
CVE-2020-6474

Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 83.0.4103.61+
Fix from $1,950 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6461

Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially p…

Fix: 81.0.4044.129+
Fix from $2,300 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6462

Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to poten…

Fix: 81.0.4044.129+
Fix from $2,300 2020-05-21
Chrome HIGH 8.8
CVE-2020-6463

Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 81.0.4044.122+
Fix from $1,950 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6465

Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6466

Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perf…

Fix: 83.0.4103.61+
Fix from $2,300 2020-05-21
Chrome HIGH 8.8
CVE-2020-6467

Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 83.0.4103.61+
Fix from $1,950 2020-05-21
Chrome CRITICAL 9.6
CVE-2020-6457

Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 81.0.4044.113+
Fix from $2,300 2020-05-21
Chrome HIGH 8.8
CVE-2020-6459

Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 81.0.4044.122+
Fix from $1,950 2020-05-21
Proxygen CRITICAL 9.8
CVE-2020-1897

A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in …

Fix: 2020.05.18.00+
Fix from $2,300 2020-05-18
Nitro Pro HIGH 8.8
CVE-2020-6074EPSS 41%

An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-…

No fix yet
Fix from $1,950 2020-05-18
Dovecot MEDIUM 5.3
CVE-2020-10958EPSS 6%

In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and …

Fix: 2.3.10.1+
Fix from $1,600 2020-05-18
Debian Linux HIGH 7.8
CVE-2018-10756

Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly exec…

Fix: 3.00+
Fix from $1,950 2020-05-15
FreeBSD HIGH 7.8
CVE-2019-15878

In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-fre…

Mitigation only
Fix from $1,950 2020-05-13
Big Ip Access Policy Manager HIGH 8.8
CVE-2020-5897

In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX component.

Fix: after 15.1.0.3
Fix from $1,950 2020-05-12