Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 8.8
CVE-2018-18336

Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18337

Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentiall…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome HIGH 8.8
CVE-2018-18339

Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a …

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Fedora MEDIUM 5.5
CVE-2018-20005

An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.

No fix yet
Fix from $1,600 2018-12-10
Android MEDIUM 6.7
CVE-2018-9517

In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execut…

Patch available
Fix from $1,600 2018-12-07
Cairo MEDIUM 6.5
CVE-2018-19876

cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leadi…

Patch available
Fix from $1,600 2018-12-05
Cx One HIGH 7.8
CVE-2018-18989

In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the…

Fix: after 9.66
Fix from $1,950 2018-12-04
Chrome HIGH 8.8
CVE-2018-6086

A double-eviction in the Incognito mode cache that lead to a user-after-free in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed…

Fix: 66.0.3359.117+
Fix from $1,950 2018-12-04
Chrome HIGH 8.8
CVE-2018-6087

A use-after-free in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr…

Fix: 66.0.3359.117+
Fix from $1,950 2018-12-04
Chrome HIGH 8.8
CVE-2018-6085

Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a c…

Fix: 66.0.3359.117+
Fix from $1,950 2018-12-04
Libsass HIGH 8.8
CVE-2018-19827

In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that may cause a denial of service…

Mitigation only
Fix from $1,950 2018-12-03
Linux Kernel HIGH 7.8
CVE-2018-19824

In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with ze…

Fix: after 4.19.6
Fix from $1,950 2018-12-03
Ubuntu Linux MEDIUM 6.5
CVE-2018-16841

Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card auth…

Fix: 4.7.12 / 4.8.7+
Fix from $1,600 2018-11-28
Android HIGH 7.8
CVE-2018-5856

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, due to a race condition, a Use After Free …

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-5904

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while list traversal in LPM status driver …

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-5919

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a use after free issue in WLAN host driver…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11261

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible Use-after-free issue i…

Patch available
Fix from $1,950 2018-11-27
Chrome HIGH 8.8
CVE-2018-6060

Use after free in WebAudio in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6072

An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome CRITICAL 9.6
CVE-2018-17462

Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML pag…

Fix: 70.0.3538.67+
Fix from $2,300 2018-11-14
Chrome HIGH 8.8
CVE-2018-17465

Incorrect implementation of object trimming in V8 in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit object corr…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-17474

Use after free in HTMLImportsController in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit heap corrupt…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Windows 10 HIGH 8.8
CVE-2018-8544EPSS 48%

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code …

Patch available
Fix from $1,950 2018-11-14
Debian Linux HIGH 7.8
CVE-2018-19216

Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.

Fix: 2.13.02+
Fix from $1,950 2018-11-12
Android HIGH 7.8
CVE-2018-9465

In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privil…

Patch available
Fix from $1,950 2018-11-06
Debian Linux HIGH 7.8
CVE-2018-9422

In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional p…

Patch available
Fix from $1,950 2018-11-06
Cx Supervisor HIGH 7.8
CVE-2018-17909

When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, wh…

Fix: after 3.4.1.0
Fix from $1,950 2018-11-05
Curl CRITICAL 9.8
CVE-2018-16840

A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and clea…

Fix: 7.62.0+
Fix from $2,300 2018-10-31
Reader HIGH 8.8
CVE-2018-17621

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is requ…

Fix: after 9.1.0.5096
Fix from $1,950 2018-10-29
Phantompdf HIGH 8.8
CVE-2018-17623

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is requ…

Fix: after 9.2.0.9297
Fix from $1,950 2018-10-29