Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Phantompdf CRITICAL 9.8
CVE-2018-17609

Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because propert…

Fix: 9.3+
Fix from $2,300 2018-09-28
Phantompdf CRITICAL 9.8
CVE-2018-17610

Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because propert…

Fix: 9.3+
Fix from $2,300 2018-09-28
Phantompdf CRITICAL 9.8
CVE-2018-17611

Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because propert…

Fix: 9.3+
Fix from $2,300 2018-09-28
V Server Firmware CRITICAL 9.8
CVE-2018-14809

Fuji Electric V-Server 4.0.3.0 and prior, A use after free vulnerability has been identified, which may allow remote code execution.

Fix: after 4.0.3.0
Fix from $2,300 2018-09-26
Chrome HIGH 8.8
CVE-2018-6054

Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome…

Fix: 64.0.3282.119+
Fix from $1,950 2018-09-25
Chrome HIGH 8.8
CVE-2018-6031

Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF f…

Fix: 64.0.3282.119+
Fix from $1,950 2018-09-25
Samsung Internet Browser HIGH 8.8
CVE-2018-10496

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Internet Browser Fixed in version 6.4.0.1…

Fix: 6.4.0.15+
Fix from $1,950 2018-09-24
Mp4v2 MEDIUM 6.5
CVE-2018-17236

The function MP4Free() in mp4property.cpp in libmp4v2 2.1.0 internally calls free() on a invalid pointer, raising a SIGABRT signal.

No fix yet
Fix from $1,600 2018-09-20
Linux Kernel HIGH 7.8
CVE-2018-17182

An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An…

Fix: 3.16.58 / 3.18.123+
Fix from $1,950 2018-09-19
Android HIGH 7.8
CVE-2018-11843

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack fo check on return value in WMA resp…

Patch available
Fix from $1,950 2018-09-18
Android HIGH 7.0
CVE-2018-11818

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, LUT configuration is passed down to drive…

Patch available
Fix from $1,950 2018-09-18
Android HIGH 7.8
CVE-2018-11300

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, callback executed from the other thread h…

Patch available
Fix from $1,950 2018-09-18
Android HIGH 7.8
CVE-2018-11281

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while calling IPA_IOC_MDFY_RT_RULE IPA IO…

Patch available
Fix from $1,950 2018-09-18
Android HIGH 7.8
CVE-2018-11286

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while accessing global variable "debug_cl…

Patch available
Fix from $1,950 2018-09-18
Linux Kernel HIGH 7.0
CVE-2018-14625

A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condi…

Patch available
Fix from $1,950 2018-09-10
Openshift Container Platform HIGH 7.8
CVE-2018-16540

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in co…

Patch available
Fix from $1,950 2018-09-05
Ubuntu Linux MEDIUM 5.5
CVE-2018-16541

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to cra…

Patch available
Fix from $1,600 2018-09-05
Linux Kernel HIGH 7.8
CVE-2018-6555

The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users…

Fix: 4.17+
Fix from $1,950 2018-09-04
Linux Kernel HIGH 7.8
CVE-2018-14619

A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when each af_alg_c…

Fix: 4.14.8+
Fix from $1,950 2018-08-30
Chrome HIGH 8.8
CVE-2017-15399

A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 62.0.3202.89+
Fix from $1,950 2018-08-28
Enterprise Linux Desktop HIGH 8.8
CVE-2017-15412

Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially e…

Fix: 2.9.5 / 63.0.3239.84+
Fix from $1,950 2018-08-28
Chrome HIGH 8.8
CVE-2017-15411

Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF fi…

Fix: 63.0.3239.84+
Fix from $1,950 2018-08-28
Chrome HIGH 8.8
CVE-2017-15410

Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF fi…

Fix: 63.0.3239.84+
Fix from $1,950 2018-08-28
Ubuntu Linux HIGH 7.8
CVE-2018-15857

An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon key…

Fix: 0.8.1+
Fix from $1,950 2018-08-25
Debian Linux HIGH 7.8
CVE-2018-10902

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_…

Patch available
Fix from $1,950 2018-08-21
Cjson CRITICAL 9.8
CVE-2018-1000217

Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corr…

Fix: 1.7.4+
Fix from $2,300 2018-08-20
Gnome Display Manager HIGH 7.8
CVE-2018-14424

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local at…

Fix: after 3.29.1
Fix from $1,950 2018-08-14
Foxit Reader HIGH 7.8
CVE-2018-3924EPSS 44%

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafte…

Fix: after 9.1.0.5096
Fix from $1,950 2018-08-01
Foxit Reader HIGH 8.8
CVE-2018-3939

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted P…

Fix: after 9.1.0.5096
Fix from $1,950 2018-08-01
Curl CRITICAL 9.8
CVE-2016-8619

The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.

Fix: 7.51.0+
Fix from $2,300 2018-08-01