Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Acrobat Dc CRITICAL 9.8
CVE-2019-7765EPSS 7%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $2,300 2019-05-22
Acrobat Dc CRITICAL 9.8
CVE-2019-7766EPSS 7%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $2,300 2019-05-22
Acrobat Dc CRITICAL 9.8
CVE-2019-7767EPSS 7%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $2,300 2019-05-22
Acrobat Dc CRITICAL 9.8
CVE-2019-7768EPSS 5%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $2,300 2019-05-22
Falco MEDIUM 5.5
CVE-2019-8339

An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to bypass the detection engine.

Fix: after 0.14.0
Fix from $1,600 2019-05-17
Gohttp CRITICAL 9.8
CVE-2019-12160

GoHTTP through 2017-07-25 has a sendHeader use-after-free.

Fix: after 2017-07-25
Fix from $2,300 2019-05-17
Windows 7 CRITICAL 9.8
CVE-2019-0708 KEVEPSS 100%

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects…

Patch available
Fix from $2,300 2019-05-16
Miniupnpd HIGH 7.5
CVE-2019-12106

The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vuln…

Patch available
Fix from $1,950 2019-05-15
SQLite HIGH 8.1
CVE-2019-5018EPSS 7%

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause …

No fix yet
Fix from $1,950 2019-05-10
Android HIGH 7.8
CVE-2019-2049

In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free. This could lead to local …

Mitigation only
Fix from $1,950 2019-05-08
Android HIGH 7.8
CVE-2019-2050

In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This could lead to local escalation o…

Mitigation only
Fix from $1,950 2019-05-08
Linux Kernel HIGH 8.1
CVE-2019-11815

An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free…

Fix: 4.4.179 / 4.9.169+
Fix from $1,950 2019-05-08
Linux Kernel HIGH 8.1
CVE-2018-20836EPSS 5%

An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/…

Fix: 3.16.72 / 3.18.140+
Fix from $1,950 2019-05-07
Linux Kernel HIGH 7.5
CVE-2019-11810EPSS 6%

An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_allo…

Fix: 3.16.69 / 3.18.139+
Fix from $1,950 2019-05-07
Linux Kernel HIGH 7.0
CVE-2019-11811

An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si mod…

Fix: 4.19.31 / 5.0.4+
Fix from $1,950 2019-05-07
Mdm9206 Firmware HIGH 7.8
CVE-2017-18156

While processing camera buffers in camera driver, a use after free condition can occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear i…

Mitigation only
Fix from $1,950 2019-05-06
Mdm9206 Firmware HIGH 7.8
CVE-2017-18157

A Use After Free Condition can occur in Thermal Engine in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, MSM…

Mitigation only
Fix from $1,950 2019-05-06
Firefox CRITICAL 9.8
CVE-2019-9796

A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single re…

Fix: 60.6.0 / 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9790

A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed w…

Fix: after 66.0
Fix from $2,300 2019-04-26
Thunderbird CRITICAL 9.8
CVE-2018-18512

A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, a…

Fix: 65.0+
Fix from $2,300 2019-04-26
Linux Kernel HIGH 7.8
CVE-2019-11487

The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists…

Fix: 4.4.216 / 4.9.181+
Fix from $1,950 2019-04-23
Libheif HIGH 8.8
CVE-2019-11471

libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to …

Patch available
Fix from $1,950 2019-04-23
Unity8 HIGH 7.8
CVE-2016-1573

Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supp…

Fix: 8.11+
Fix from $1,950 2019-04-22
Android HIGH 8.8
CVE-2019-2029

In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no a…

Patch available
Fix from $1,950 2019-04-19
Android CRITICAL 9.8
CVE-2019-2030

In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could lead to remote code execution with no additional e…

Patch available
Fix from $2,300 2019-04-19
Android HIGH 7.8
CVE-2019-2033

In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional executio…

Patch available
Fix from $1,950 2019-04-19
Ubuntu Linux HIGH 7.5
CVE-2019-3885

A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via t…

Fix: after 2.0.1
Fix from $1,950 2019-04-18
Common Components MEDIUM 6.6
CVE-2019-6556

When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if i…

Fix: after 2019-01
Fix from $1,600 2019-04-10
Advance Steel HIGH 7.8
CVE-2019-7360

An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD …

Mitigation only
Fix from $1,950 2019-04-09
HTTP Server HIGH 7.8
CVE-2019-0211 KEVEPSS 65%

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads …

Fix: after 2.4.38
Fix from $1,950 2019-04-08