Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Xplatform HIGH 7.8
CVE-2019-19162

A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it.

Fix: after 9.2.2
Fix from $1,950 2020-05-11
Fedora HIGH 7.8
CVE-2020-11866

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.

Fix: after 1.0.11
Fix from $1,950 2020-05-11
Linux Kernel MEDIUM 6.4
CVE-2020-10690

There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation…

Fix: 5.5+
Fix from $1,600 2020-05-08
Linux Kernel HIGH 7.8
CVE-2020-12657

An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.

Fix: 5.6.5+
Fix from $1,950 2020-05-05
Fedora MEDIUM 5.3
CVE-2020-10700

A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious …

Fix: 4.10.15 / 4.11.8+
Fix from $1,600 2020-05-04
Ubuntu Linux HIGH 7.0
CVE-2020-1752

A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths co…

Fix: 2.32.0+
Fix from $1,950 2020-04-30
Linux Kernel MEDIUM 6.7
CVE-2020-12464

usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka …

Fix: 3.16.85 / 4.4.221+
Fix from $1,600 2020-04-29
FreeBSD CRITICAL 9.8
CVE-2019-15874

In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, inco…

Patch available
Fix from $2,300 2020-04-29
Qt CRITICAL 9.8
CVE-2020-12267

setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.

Patch available
Fix from $2,300 2020-04-27
Firefox HIGH 8.1
CVE-2020-6819 KEV

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in th…

Fix: 68.6.1 / 68.7.0+
Fix from $1,950 2020-04-24
Phantompdf HIGH 7.8
CVE-2020-10906

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is requi…

Fix: after 9.7.1.29511
Fix from $1,950 2020-04-22
Phantompdf HIGH 7.8
CVE-2020-10907

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is requi…

Fix: after 9.7.1.29511
Fix from $1,950 2020-04-22
Phantompdf HIGH 7.8
CVE-2020-10899

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is requi…

Fix: after 9.7.1.29511
Fix from $1,950 2020-04-22
Phantompdf HIGH 7.8
CVE-2020-10900

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is requi…

Fix: after 9.7.1.29511
Fix from $1,950 2020-04-22
Fedora MEDIUM 6.5
CVE-2020-1983

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

Fix: after 4.2.0
Fix from $1,600 2020-04-22
Fbx Software Development Kit HIGH 8.8
CVE-2020-7082

A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it.

Fix: after 2019.0
Fix from $1,950 2020-04-17
Ubuntu Linux HIGH 8.8
CVE-2020-11793

A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute…

Fix: 2.28.1+
Fix from $1,950 2020-04-17
Apq8009 Firmware HIGH 7.0
CVE-2019-14070

Possible use after free issue in pcm volume controls due to race condition exist in private data used in mixer controls in Snapdragon Auto, Snapdrago…

Patch available
Fix from $1,950 2020-04-16
Nicobar Firmware HIGH 7.8
CVE-2019-10621

Use after free issue when MAP and UNMAP calls at same time as data structure used my MAP may be freed by UNMAP function in Snapdragon Auto, Snapdrago…

Patch available
Fix from $1,950 2020-04-16
Vm Virtualbox HIGH 8.2
CVE-2020-2758

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.40 / 6.0.20+
Fix from $1,950 2020-04-15
Chrome HIGH 8.8
CVE-2020-6436

Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 81.0.4044.92+
Fix from $1,950 2020-04-13
Chrome HIGH 8.8
CVE-2020-6448

Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 81.0.4044.92+
Fix from $1,950 2020-04-13
Chrome HIGH 8.8
CVE-2020-6450

Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 80.0.3987.162+
Fix from $1,950 2020-04-13
Chrome HIGH 8.8
CVE-2020-6451

Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 80.0.3987.162+
Fix from $1,950 2020-04-13
Chrome HIGH 8.8
CVE-2020-6454

Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to pote…

Fix: 81.0.4044.92+
Fix from $1,950 2020-04-13
Chrome HIGH 8.8
CVE-2020-6423

Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 81.0.4044.92+
Fix from $1,950 2020-04-13
Chrome HIGH 8.8
CVE-2020-6434

Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 81.0.4044.92+
Fix from $1,950 2020-04-13
SQLite CRITICAL 9.8
CVE-2020-11656EPSS 8%

In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELEC…

Fix: after 12.0.3
Fix from $2,300 2020-04-09
Android HIGH 8.1
CVE-2018-21040

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is a race condition with a resultant …

Mitigation only
Fix from $1,950 2020-04-08
Android HIGH 8.1
CVE-2018-21084

An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition with a resultant read-after-fre…

Mitigation only
Fix from $1,950 2020-04-08