Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
H2o CRITICAL 9.1
CVE-2016-7835

Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly…

Fix: after 2.0.4
Fix from $2,300 2017-06-09
PHP CRITICAL 9.8
CVE-2016-4473EPSS 6%

/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to C…

Patch available
Fix from $2,300 2017-06-08
Radare2 MEDIUM 5.5
CVE-2017-9520

The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and applicati…

Patch available
Fix from $1,600 2017-06-08
Android HIGH 7.8
CVE-2014-9926

In GNSS in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Android HIGH 7.8
CVE-2014-9930

In WCDMA in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Android HIGH 7.8
CVE-2014-9946

In Core Kernel in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Contiki HIGH 7.5
CVE-2017-7295

An issue was discovered in Contiki Operating System 3.0. A use-after-free vulnerability exists in httpd-simple.c in cc26xx-web-demo httpd, where upon…

Mitigation only
Fix from $1,950 2017-05-28
Poweriso HIGH 7.8
CVE-2017-2823EPSS 9%

A use-after-free vulnerability exists in the .ISO parsing functionality of PowerISO 6.8. A specially crafted .ISO file can cause a vulnerability resu…

No fix yet
Fix from $1,950 2017-05-24
Autotrace HIGH 7.5
CVE-2017-9182

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (use-after-free and invalid heap read), related to the GET_CO…

Mitigation only
Fix from $1,950 2017-05-23
Autotrace HIGH 7.5
CVE-2017-9190

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid free), related to the free_bitmap function in bitmap…

Mitigation only
Fix from $1,950 2017-05-23
Chrome HIGH 8.8
CVE-2016-5177

Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly hav…

Fix: after 53.0.2785.129
Fix from $1,950 2017-05-23
Ghostscript CRITICAL 9.8
CVE-2016-7978EPSS 5%

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .s…

Patch available
Fix from $2,300 2017-05-23
Iphone Os CRITICAL 9.8
CVE-2017-2513

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: after 10.12.4
Fix from $2,300 2017-05-22
Debian Linux CRITICAL 9.8
CVE-2017-2518EPSS 5%

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $2,300 2017-05-22
Linux Kernel HIGH 7.8
CVE-2017-7487

The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a den…

Fix: 3.2.89 / 3.16.44+
Fix from $1,950 2017-05-14
Yara HIGH 7.5
CVE-2017-8929

The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and applicatio…

Patch available
Fix from $1,950 2017-05-14
Android HIGH 7.8
CVE-2017-8246

In function msm_pcm_playback_close() in all Android releases from CAF using the Linux kernel, prtd is assigned substream->runtime->private_data. Late…

Mitigation only
Fix from $1,950 2017-05-12
Windows 10 1507 HIGH 7.8
CVE-2017-0263 KEVEPSS 10%

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…

Patch available
Fix from $1,950 2017-05-12
Office HIGH 7.8
CVE-2017-0261 KEVEPSS 78%

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle ob…

Patch available
Fix from $1,950 2017-05-12
Backup Exec CRITICAL 9.8
CVE-2017-8895EPSS 67%

In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability i…

Fix: 14.1.1786.1126 / 14.2.1180.3160+
Fix from $2,300 2017-05-10
Swftools HIGH 7.8
CVE-2017-7698

A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF document, po…

Fix: after 0.9.2
Fix from $1,950 2017-05-10
Enterprise Linux HIGH 8.8
CVE-2017-3071EPSS 6%

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploita…

Fix: after 25.0.0.163
Fix from $1,950 2017-05-09
Enterprise Linux HIGH 8.8
CVE-2017-3073

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multiple mask properties of display…

Fix: after 25.0.0.163
Fix from $1,950 2017-05-09
Debian Linux MEDIUM 5.5
CVE-2017-8846

The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and applicati…

Patch available
Fix from $1,600 2017-05-08
Linux Kernel HIGH 7.0
CVE-2014-9940

The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a den…

Fix: 3.16.45 / 3.18.52+
Fix from $1,950 2017-05-02
Chrome HIGH 8.8
CVE-2017-5031

A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a …

Fix: after 57.0.2987.75
Fix from $1,950 2017-04-24
Chrome HIGH 8.8
CVE-2017-5034

A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Linux and Windows allowed a remote attacker to perform an out of bounds memory …

Fix: after 57.0.2987.75
Fix from $1,950 2017-04-24
Chrome HIGH 7.8
CVE-2017-5036

A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker…

Fix: after 57.0.2987.100
Fix from $1,950 2017-04-24
Chrome MEDIUM 6.3
CVE-2017-5038

Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker…

Fix: after 57.0.2987.75
Fix from $1,600 2017-04-24
Chrome HIGH 7.8
CVE-2017-5039

A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker…

Fix: after 57.0.2987.100
Fix from $1,950 2017-04-24