Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Acrobat HIGH 8.8
CVE-2017-11219EPSS 7%

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable u…

Fix: after 17.011.30066
Fix from $1,950 2017-08-11
Acrobat HIGH 8.8
CVE-2017-11223EPSS 7%

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable u…

Fix: after 17.011.30066
Fix from $1,950 2017-08-11
Acrobat HIGH 8.8
CVE-2017-11224EPSS 7%

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable u…

Fix: after 17.011.30066
Fix from $1,950 2017-08-11
Acrobat HIGH 8.8
CVE-2017-11231EPSS 6%

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable u…

Fix: after 17.011.30066
Fix from $1,950 2017-08-11
Acrobat MEDIUM 6.5
CVE-2017-11232

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable u…

Fix: after 17.011.30066
Fix from $1,600 2017-08-11
Acrobat HIGH 8.8
CVE-2017-11235EPSS 6%

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable u…

Fix: after 17.011.30066
Fix from $1,950 2017-08-11
Android HIGH 7.8
CVE-2017-0727

A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-33004354.

Patch available
Fix from $1,950 2017-08-09
Imagemagick MEDIUM 6.5
CVE-2017-12671

In ImageMagick 7.0.6-3, a missing NULL assignment was found in coders/png.c, leading to an invalid free in the function RelinquishMagickMemory in Mag…

Patch available
Fix from $1,600 2017-08-07
Ntp HIGH 8.8
CVE-2015-7849EPSS 17%

Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbit…

Fix: 4.2.8 / 4.3.77+
Fix from $1,950 2017-08-07
Clamav MEDIUM 5.5
CVE-2017-6420

The wwunpack function in libclamav/wwunpack.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (use-after-free) via a crafted PE…

Patch available
Fix from $1,600 2017-08-07
Binutils HIGH 7.8
CVE-2017-12448

The bfd_cache_close function in bfd/cache.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier…

Fix: after 2.29
Fix from $1,950 2017-08-04
Imagemagick MEDIUM 6.5
CVE-2017-12431

In ImageMagick 7.0.6-1, a use-after-free vulnerability was found in the function ReadWMFImage in coders/wmf.c, which allows attackers to cause a deni…

Patch available
Fix from $1,600 2017-08-04
Debian Linux HIGH 7.8
CVE-2017-9612

The Ins_IP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (use-after-free and …

No fix yet
Fix from $1,950 2017-07-26
Fedora MEDIUM 5.5
CVE-2015-5221

Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote…

Fix: after 1.900.1
Fix from $1,600 2017-07-25
Graphicsmagick HIGH 8.8
CVE-2017-11403EPSS 25%

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted fi…

Patch available
Fix from $1,950 2017-07-18
Exiv2 MEDIUM 6.5
CVE-2017-11337

There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of s…

Mitigation only
Fix from $1,600 2017-07-17
HTTP Server HIGH 7.5
CVE-2017-9789EPSS 9%

When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, r…

Mitigation only
Fix from $1,950 2017-07-13
Linux Kernel HIGH 7.8
CVE-2017-11176

The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space …

Fix: 3.2.92 / 3.16.47+
Fix from $1,950 2017-07-11
Vim HIGH 7.8
CVE-2017-11109

Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NO…

Mitigation only
Fix from $1,950 2017-07-08
Irssi CRITICAL 9.8
CVE-2017-10966

An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free t…

Fix: after 1.0.3
Fix from $2,300 2017-07-07
Dbd Mysql CRITICAL 9.8
CVE-2017-10788

The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly …

Fix: after 4.043
Fix from $2,300 2017-07-01
Ubuntu Linux HIGH 7.8
CVE-2017-10686

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the to…

Patch available
Fix from $1,950 2017-06-29
Xml Libxml CRITICAL 9.8
CVE-2017-10672EPSS 8%

Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a r…

Fix: after 2.0129
Fix from $2,300 2017-06-29
Flash Player CRITICAL 9.8
CVE-2016-0959

Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, …

Fix: after 20.0.0.235
Fix from $2,300 2017-06-27
Iphone Os HIGH 8.8
CVE-2017-2491EPSS 8%

Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remote attackers to execute arbitr…

Fix: after 10.2.1
Fix from $1,950 2017-06-27
Enterprise Linux HIGH 7.5
CVE-2017-9953

There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input will lead to a remote denial o…

No fix yet
Fix from $1,950 2017-06-26
Radare2 MEDIUM 5.5
CVE-2017-9762

The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application c…

Patch available
Fix from $1,600 2017-06-19
Android HIGH 7.0
CVE-2017-7370

In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.

Patch available
Fix from $1,950 2017-06-13
Android HIGH 7.8
CVE-2017-7371

In all Android releases from CAF using the Linux kernel, a data pointer is potentially used after it has been freed when SLIMbus is turned off by Blu…

Patch available
Fix from $1,950 2017-06-13
Debian Linux HIGH 7.8
CVE-2017-9527

The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and applicati…

Fix: after 1.2.0
Fix from $1,950 2017-06-11