Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Android CRITICAL 9.8
CVE-2017-14918

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the GPS location wireless interfac…

Mitigation only
Fix from $2,300 2017-12-05
Android HIGH 7.0
CVE-2017-9703

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in a Camera driver c…

Patch available
Fix from $1,950 2017-12-05
Android HIGH 7.5
CVE-2017-11031

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the VIDIOC_G_SDE_ROTATOR_FENCE ioctl …

Mitigation only
Fix from $1,950 2017-12-05
Android HIGH 7.8
CVE-2017-11033

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the coresight-tmc driver, a simult…

Mitigation only
Fix from $1,950 2017-12-05
Android HIGH 7.0
CVE-2017-11044

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a KGSL driver function, a race con…

Mitigation only
Fix from $1,950 2017-12-05
Android HIGH 7.0
CVE-2017-11045

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a camera driver function, a race c…

Mitigation only
Fix from $1,950 2017-12-05
Linux Kernel HIGH 7.8
CVE-2017-8824

The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of servic…

Fix: 3.2.97 / 3.16.52+
Fix from $1,950 2017-12-05
Debian Linux HIGH 8.1
CVE-2017-8823

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-a…

Fix: 0.2.5.16 / 0.2.8.17+
Fix from $1,950 2017-12-03
Linux Kernel HIGH 7.8
CVE-2017-17052

The mm_init function in kernel/fork.c in the Linux kernel before 4.12.10 does not clear the ->exe_file member of a new process's mm_struct, allowing …

Fix: 4.9.46 / 4.12.10+
Fix from $1,950 2017-11-29
Linux Kernel HIGH 7.0
CVE-2017-17053

The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctly handle errors from LDT tabl…

Fix: 4.4.153 / 4.9.46+
Fix from $1,950 2017-11-29
Xen HIGH 8.8
CVE-2017-17045

An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a …

Fix: after 4.9.1
Fix from $1,950 2017-11-28
Ubuntu Linux CRITICAL 9.8
CVE-2017-14746EPSS 10%

Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.

Fix: 4.5.0 / 4.5.15+
Fix from $2,300 2017-11-27
Debian Linux CRITICAL 9.8
CVE-2017-16943EPSS 47%

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of…

Patch available
Fix from $2,300 2017-11-25
Linux Kernel HIGH 7.8
CVE-2017-16939

The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denia…

Fix: 3.2.97 / 3.16.52+
Fix from $1,950 2017-11-24
Nova 2 Firmware HIGH 7.8
CVE-2017-8203

The Bastet Driver of Nova 2 Plus,Nova 2 Huawei smart phones with software of Versions earlier than BAC-AL00C00B173,Versions earlier than PIC-AL00C00B…

Mitigation only
Fix from $1,950 2017-11-22
Mate 9 Firmware HIGH 7.8
CVE-2017-8142

The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and …

Mitigation only
Fix from $1,950 2017-11-22
Vicky Al00a Firmware HIGH 7.8
CVE-2017-8160

The Madapt Driver of some Huawei smart phones with software Earlier than Vicky-AL00AC00B172 versions,Vicky-AL00CC768B122,Vicky-TL00AC01B167,Earlier t…

Mitigation only
Fix from $1,950 2017-11-22
Lynx MEDIUM 5.3
CVE-2017-1000211

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a c…

Patch available
Fix from $1,600 2017-11-17
Gravity CRITICAL 9.8
CVE-2017-1000172

Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sublexer' pointer has been freed…

No fix yet
Fix from $2,300 2017-11-17
Android HIGH 7.8
CVE-2017-0861

Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecifi…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-11091

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function mdss_rotator_ioctl in…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-11092

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the KGSL driver function kgsl_ioct…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-11024

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in the rmnet USB con…

Patch available
Fix from $1,950 2017-11-16
Linux Kernel HIGH 7.8
CVE-2017-15115

The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off act…

Fix: 3.2.96 / 3.16.51+
Fix from $1,950 2017-11-15
Psftpd MEDIUM 5.9
CVE-2017-15271EPSS 9%

A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentic…

No fix yet
Fix from $1,600 2017-11-15
Libebml2 MEDIUM 6.5
CVE-2017-12780

The ReadData function in ebmlstring.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (invalid free and applicati…

Fix: after 2012-08-26
Fix from $1,600 2017-11-10
Linux Kernel MEDIUM 6.6
CVE-2017-16648

The dvb_frontend_free function in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel through 4.13.11 allows local users to cause a denial of s…

Fix: after 4.13.11
Fix from $1,600 2017-11-07
Mongoose CRITICAL 9.8
CVE-2017-2922

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket…

No fix yet
Fix from $2,300 2017-11-07
Mongoose CRITICAL 9.8
CVE-2017-2891

An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CG…

No fix yet
Fix from $2,300 2017-11-07
Linux Kernel MEDIUM 6.6
CVE-2017-16525

The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of …

Fix: 3.2.96 / 3.10.108+
Fix from $1,600 2017-11-04