Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Linux Kernel MEDIUM 6.6
CVE-2017-16527

sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and syste…

Fix: 3.2.95 / 3.16.50+
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16528

sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (snd_rawmidi_dev_seq_free use-after-free an…

Fix: 4.1.47 / 4.4.99+
Fix from $1,600 2017-11-04
Foxit Reader HIGH 8.8
CVE-2017-10941

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is req…

Patch available
Fix from $1,950 2017-10-31
Foxit Reader HIGH 8.8
CVE-2017-10945

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is req…

Patch available
Fix from $1,950 2017-10-31
Foxit Reader HIGH 8.8
CVE-2017-10946

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.1.6871. User interaction is requ…

Patch available
Fix from $1,950 2017-10-31
Foxit Reader HIGH 8.8
CVE-2017-10947

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.1.6871. User interaction is requ…

Patch available
Fix from $1,950 2017-10-31
Foxit Reader HIGH 8.8
CVE-2017-10948

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.1.6871. User interaction is requ…

Patch available
Fix from $1,950 2017-10-31
Chrome HIGH 8.8
CVE-2017-5111

A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory…

Fix: 61.0.3163.79+
Fix from $1,950 2017-10-27
Chrome HIGH 8.0
CVE-2017-5074

A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read …

Fix: 59.0.3071.86+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5080

A use after free in credit card autofill in Google Chrome prior to 59.0.3071.86 for Linux and Windows allowed a remote attacker to perform an out of …

Fix: 59.0.3071.86+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5087

A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attack…

Fix: 59.0.3071.104 / 59.0.3071.117+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5091

A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out…

Fix: 60.0.3112.78+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5098EPSS 16%

A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform an out of bou…

Fix: after 60.0.3112.78
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5100

A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to perform an out of bounds memory read via a c…

Fix: after 60.0.3112.78
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5055

A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memo…

Fix: 57.0.2987.133+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5056

A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attack…

Fix: 57.0.2987.132 / 57.0.2987.133+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5058

A use after free in PrintPreview in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially perform out of bounds me…

Fix: 58.0.3029.81+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5062

A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote at…

Fix: 58.0.3029.81 / 58.0.3029.83+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5073

Use after free in print preview in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a …

Fix: 59.0.3071.86 / 59.0.3071.92+
Fix from $1,950 2017-10-27
Irssi HIGH 7.5
CVE-2017-15227

Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting i…

Fix: after 1.0.4
Fix from $1,950 2017-10-22
Debian Linux MEDIUM 5.5
CVE-2017-15642

In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.

Mitigation only
Fix from $1,600 2017-10-19
Fedora CRITICAL 9.8
CVE-2015-7687

Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vec…

Fix: after 5.7.1
Fix from $2,300 2017-10-16
Linux Kernel HIGH 7.0
CVE-2017-15265

Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly h…

Fix: 3.2.95 / 3.10.108+
Fix from $1,950 2017-10-16
Mupdf HIGH 7.8
CVE-2017-15369

The build_filter_chain function in pdf/pdf-stream.c in Artifex MuPDF before 2017-09-25 mishandles a certain case where a variable may reside in a reg…

Fix: after 1.11
Fix from $1,950 2017-10-16
Debian Linux HIGH 8.8
CVE-2017-15238

ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.

Patch available
Fix from $1,950 2017-10-11
Android HIGH 7.8
CVE-2017-11048

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a display driver function, a Use A…

Mitigation only
Fix from $1,950 2017-10-10
Imagemagick MEDIUM 6.5
CVE-2017-14989

A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the application via a crafted font f…

Patch available
Fix from $1,600 2017-10-03
Mesos HIGH 7.5
CVE-2017-9790

When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1…

Fix: after 1.1.2
Fix from $1,950 2017-09-29
Exiv2 MEDIUM 5.5
CVE-2017-14857

In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of …

No fix yet
Fix from $1,600 2017-09-29
Android HIGH 7.8
CVE-2017-8277

In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function msm_dba_register_client, if the client registers fail…

Fix: after 8.0
Fix from $1,950 2017-09-21