Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Safari HIGH 8.8
CVE-2019-8584

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Saf…

Fix: 7.12 / 10.4+
Fix from $1,950 2019-12-18
Safari HIGH 8.8
CVE-2019-8556

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Wind…

Fix: 7.11 / 12.1+
Fix from $1,950 2019-12-18
Mac Os X HIGH 7.8
CVE-2019-8526 KEV

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain…

Fix: 10.14.4+
Fix from $1,950 2019-12-18
Safari HIGH 8.8
CVE-2019-7285

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Wind…

Fix: 7.11 / 12.1+
Fix from $1,950 2019-12-18
Apq8009 Firmware HIGH 7.8
CVE-2019-10518

Use after free of a pointer in iWLAN scenario during netmgr state transition to CONNECT in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer I…

Mitigation only
Fix from $1,950 2019-12-18
Fedora HIGH 7.5
CVE-2019-3994

ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash th…

Fix: after 3.1.4-57bea22
Fix from $1,950 2019-12-17
Linux Kernel MEDIUM 5.5
CVE-2019-19813

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a…

No fix yet
Fix from $1,600 2019-12-17
Linux Kernel HIGH 7.8
CVE-2019-19807

In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is relate…

Fix: 4.9.201 / 4.14.154+
Fix from $1,950 2019-12-15
Linux Kernel MEDIUM 5.5
CVE-2019-19767

The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xatt…

Fix: 5.4.2+
Fix from $1,600 2019-12-12
Linux Kernel HIGH 7.5
CVE-2019-19768

In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out…

Mitigation only
Fix from $1,950 2019-12-12
Linux Kernel MEDIUM 6.7
CVE-2019-19769

In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h).

Fix: after 5.3.10
Fix from $1,600 2019-12-12
Linux Kernel HIGH 8.2
CVE-2019-19770

In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or…

Fix: after 4.19.83
Fix from $1,950 2019-12-12
Apq8098 Firmware MEDIUM 5.5
CVE-2019-10484

Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deallocated during previous comman…

Mitigation only
Fix from $1,600 2019-12-12
Apq8009 Firmware HIGH 8.1
CVE-2019-10494

Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapd…

Patch available
Fix from $1,950 2019-12-12
Chrome HIGH 8.8
CVE-2019-13729

Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 79.0.3945.79+
Fix from $1,950 2019-12-10
Chrome HIGH 8.8
CVE-2019-13732

Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 79.0.3945.79+
Fix from $1,950 2019-12-10
Chrome HIGH 8.8
CVE-2019-13725

Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

Fix: 79.0.3945.79+
Fix from $1,950 2019-12-10
Linux Kernel HIGH 7.8
CVE-2019-19448

In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call ca…

Fix: 4.4.233 / 4.9.233+
Fix from $1,950 2019-12-08
Linux Kernel HIGH 7.8
CVE-2019-19447

In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4…

Fix: 3.16.82 / 4.4.208+
Fix from $1,950 2019-12-08
Android HIGH 7.5
CVE-2019-2230

In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use after free. This could lead to …

Patch available
Fix from $1,950 2019-12-06
Android HIGH 7.8
CVE-2019-2217

In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege w…

Mitigation only
Fix from $1,950 2019-12-06
Radare2 HIGH 7.8
CVE-2019-19590

In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer …

Fix: after 4.0.0
Fix from $1,950 2019-12-05
Proxygen CRITICAL 9.8
CVE-2019-11940

In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table i…

Fix: after 2017.04.03.00
Fix from $2,300 2019-12-04
Goahead CRITICAL 9.8
CVE-2019-5096EPSS 67%

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application …

No fix yet
Fix from $2,300 2019-12-03
Linux Kernel HIGH 7.8
CVE-2019-19543

In the Linux kernel before 5.1.6, there is a use-after-free in serial_ir_init_module() in drivers/media/rc/serial_ir.c.

Fix: 5.1.6+
Fix from $1,950 2019-12-03
Linux Kernel MEDIUM 6.1
CVE-2019-19528

In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driv…

Fix: 5.3.7+
Fix from $1,600 2019-12-03
Linux Kernel MEDIUM 6.3
CVE-2019-19529

In the Linux kernel before 5.3.11, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c d…

Fix: 5.3.11+
Fix from $1,600 2019-12-03
Linux Kernel MEDIUM 6.8
CVE-2019-19531

In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/yurex.c driver, …

Fix: 5.2.9+
Fix from $1,600 2019-12-03
Linux Kernel MEDIUM 6.8
CVE-2019-19527

In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driv…

Fix: 3.16.79 / 4.4.190+
Fix from $1,600 2019-12-03
Linux Kernel HIGH 7.8
CVE-2019-19377

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btr…

Fix: 4.19.156 / 5.4.33+
Fix from $1,950 2019-11-29