Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 8.8
CVE-2018-20066

Incorrect object lifecycle in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via …

Fix: 71.0.3578.80+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-16085

A use after free in ResourceCoordinator in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-17457

An object lifecycle issue in Blink could lead to a use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to exe…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-16065

A Javascript reentrancy issues that caused a use-after-free in V8 in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitra…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16066

A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16067

A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome HIGH 8.8
CVE-2018-16071

A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted vide…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Wireshark MEDIUM 5.5
CVE-2019-5721

In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management a…

Fix: after 2.4.11
Fix from $1,600 2019-01-08
Windows 10 HIGH 7.8
CVE-2019-0570

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privi…

Patch available
Fix from $1,950 2019-01-08
Linux Kernel HIGH 8.8
CVE-2018-16882

A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. …

Fix: 4.14.91 / 4.19.13+
Fix from $1,950 2019-01-03
Mdm9206 Firmware HIGH 7.8
CVE-2017-18328

Use after free in QSH client rule processing in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM96…

Mitigation only
Fix from $1,950 2019-01-03
Binutils MEDIUM 5.5
CVE-2018-20623

In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a…

No fix yet
Fix from $1,600 2018-12-31
Fedora MEDIUM 5.5
CVE-2018-20592

In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnera…

No fix yet
Fix from $1,600 2018-12-30
Netwide Assembler MEDIUM 5.5
CVE-2018-20535

There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a li…

No fix yet
Fix from $1,600 2018-12-28
Netwide Assembler MEDIUM 5.5
CVE-2018-20538

There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during cert…

No fix yet
Fix from $1,600 2018-12-28
Debian Linux HIGH 8.8
CVE-2018-1000878

libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability …

Fix: 3.4.0+
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11988

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Un-trusted pointer de-reference issue by a…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11960

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition can occur in th…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11983

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Error in kernel observed while accessing f…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2018-11984

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition and an out-of-b…

Patch available
Fix from $1,950 2018-12-20
Android HIGH 7.8
CVE-2017-9704

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, There is no synchronization between msm_vb…

Patch available
Fix from $1,950 2018-12-20
Ubuntu Linux CRITICAL 9.8
CVE-2018-15126EPSS 12%

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension th…

Fix: 0.9.12+
Fix from $2,300 2018-12-19
Ubuntu Linux HIGH 8.1
CVE-2018-6307EPSS 27%

LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension th…

Fix: 0.9.12+
Fix from $1,950 2018-12-19
Linux Kernel HIGH 8.0
CVE-2018-16884

A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_proce…

Fix: 3.16.65 / 3.18.133+
Fix from $1,950 2018-12-18
Ubuntu Linux MEDIUM 5.5
CVE-2018-19364

hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-…

Fix: after 3.0.0
Fix from $1,600 2018-12-13
Agent CRITICAL 9.8
CVE-2018-6703

Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attacker…

Fix: 5.6.0+
Fix from $2,300 2018-12-11
Chrome HIGH 8.8
CVE-2018-18340

Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption v…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18343

Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploi…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18356

An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-17481

Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potentially exploit heap corruption…

Fix: 71.0.3578.98+
Fix from $1,950 2018-12-11