A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable cras…
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC en…
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference count…
A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in a potenti…
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable c…
A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the main thread …
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerab…
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content …
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potenti…
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, re…
A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. Thi…
A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crash. This…
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This…
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitab…
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially explo…
A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This re…
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some case…
A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially ex…
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This…
A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through …
A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from…
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results i…
A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potent…
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished…
A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is f…
A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due…
A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially e…
A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results…
A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a…
A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tre…