Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
FreeBSD CRITICAL 9.8
CVE-2018-6916

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p7, 10.4-STABLE, 10.4-RELEASE-p7, and 10.3-RELEASE-p28, the kernel does not properly validate IPsec packe…

Fix: 11.1+
Fix from $2,300 2018-03-09
Graphicsmagick HIGH 8.8
CVE-2017-18220

The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/b…

Patch available
Fix from $1,950 2018-03-05
Linux Kernel HIGH 7.8
CVE-2017-18218

In drivers/net/ethernet/hisilicon/hns/hns_enet.c in the Linux kernel before 4.13, local users can cause a denial of service (use-after-free and BUG) …

Fix: 4.9.92 / 4.13+
Fix from $1,950 2018-03-05
Tor HIGH 7.5
CVE-2018-0491EPSS 15%

A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because t…

Fix: 0.3.2.10+
Fix from $1,950 2018-03-05
Debian Linux CRITICAL 9.8
CVE-2018-7551

There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial o…

No fix yet
Fix from $2,300 2018-02-28
Debian Linux CRITICAL 9.8
CVE-2018-7554

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of se…

No fix yet
Fix from $2,300 2018-02-28
Mathtype CRITICAL 9.8
CVE-2018-6641EPSS 6%

An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a…

No fix yet
Fix from $2,300 2018-02-28
Linux Kernel HIGH 7.0
CVE-2017-18202

The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which allows attackers to cause a de…

Fix: 4.9.68 / 4.14.4+
Fix from $1,950 2018-02-27
Acrobat HIGH 8.8
CVE-2018-4911EPSS 10%

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier …

Fix: after 18.009.20050
Fix from $1,950 2018-02-27
Acrobat HIGH 8.8
CVE-2018-4913EPSS 14%

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier …

Fix: after 18.009.20050
Fix from $1,950 2018-02-27
Acrobat HIGH 8.8
CVE-2018-4892EPSS 12%

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier …

Fix: after 18.009.20050
Fix from $1,950 2018-02-27
Acrobat HIGH 8.8
CVE-2018-4902EPSS 12%

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier …

Fix: after 18.009.20050
Fix from $1,950 2018-02-27
Acrobat HIGH 8.8
CVE-2018-4888EPSS 12%

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier …

Fix: after 18.009.20050
Fix from $1,950 2018-02-27
Windows 7 HIGH 7.0
CVE-2018-7249

An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped i…

No fix yet
Fix from $1,950 2018-02-26
Android HIGH 7.8
CVE-2017-15820

In all Qualcomm products with Android releases from CAF using the Linux kernel, in a KGSL IOCTL handler, a Use After Free Condition can potentially o…

Mitigation only
Fix from $1,950 2018-02-23
Smartos HIGH 7.8
CVE-2018-1166

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An …

Mitigation only
Fix from $1,950 2018-02-21
Debian Linux CRITICAL 9.8
CVE-2018-7053

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected orde…

Fix: 1.0.7+
Fix from $2,300 2018-02-15
Ubuntu Linux CRITICAL 9.8
CVE-2018-7054

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE:…

Fix: 1.0.7+
Fix from $2,300 2018-02-15
Mate 9 Pro Firmware MEDIUM 5.5
CVE-2017-15347

Huawei Mate 9 Pro mobile phones with software of versions earlier than LON-AL00BC00B235 have a use after free (UAF) vulnerability. An attacker tricks…

Mitigation only
Fix from $1,600 2018-02-15
Debian Linux HIGH 7.8
CVE-2018-1000051

Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This a…

Patch available
Fix from $1,950 2018-02-09
Sumatrapdf HIGH 7.8
CVE-2013-2830

Use-after-free vulnerability in SumatraPDF Reader 2.x before 2.2.1 allows remote attackers to execute arbitrary code via a crafted PDF file.

Fix: 2.2.1+
Fix from $1,950 2018-02-08
Chrome HIGH 8.8
CVE-2017-5126

A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF …

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5127

Use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF fi…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5129

A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a …

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome MEDIUM 6.5
CVE-2017-15395

A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 62.0.3202.62+
Fix from $1,600 2018-02-07
Foxit Reader HIGH 7.8
CVE-2016-6168

Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (ap…

Fix: after 7.3.4.311
Fix from $1,950 2018-02-07
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-4877EPSS 8%

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Pri…

Fix: 28.0.0.161+
Fix from $2,300 2018-02-06
Enterprise Linux Desktop HIGH 7.8
CVE-2018-4878 KEVEPSS 90%

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Pri…

Fix: 28.0.0.161+
Fix from $1,950 2018-02-06
Libwebm CRITICAL 9.8
CVE-2018-6548

A use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, its property frame_ would not …

Fix: after 1.0.0.27
Fix from $2,300 2018-02-02
Debian Linux HIGH 8.8
CVE-2018-6359

The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause a denial o…

Fix: after 0.4.8
Fix from $1,950 2018-01-27