Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Debian Linux HIGH 7.5
CVE-2017-5194

Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to cause a denial of service (crash) via an invalid nick message.

Fix: 0.8.21+
Fix from $1,950 2017-03-03
Linux Kernel HIGH 7.0
CVE-2017-6346

Race condition in net/packet/af_packet.c in the Linux kernel before 4.9.13 allows local users to cause a denial of service (use-after-free) or possib…

Fix: 3.2.87 / 3.10.106+
Fix from $1,950 2017-03-01
Mp3splt MEDIUM 5.5
CVE-2017-5666

The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a c…

No fix yet
Fix from $1,600 2017-03-01
Libiberty MEDIUM 5.5
CVE-2016-4487

Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…

Mitigation only
Fix from $1,600 2017-02-24
Libiberty MEDIUM 5.5
CVE-2016-4488

Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…

Mitigation only
Fix from $1,600 2017-02-24
Afpl Ghostscript HIGH 7.8
CVE-2017-6196

Multiple use-after-free vulnerabilities in the gx_image_enum_begin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739…

Fix: after 8452f9238959a4d518af365812bf031fe4d8d4b7
Fix from $1,950 2017-02-24
Ubuntu Linux HIGH 7.5
CVE-2016-10109

Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsLi…

Fix: after 1.8.19
Fix from $1,950 2017-02-23
Mac Os X HIGH 7.8
CVE-2017-2353EPSS 6%

An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attacker…

Fix: after 10.12.2
Fix from $1,950 2017-02-20
Iphone Os HIGH 7.8
CVE-2017-2360EPSS 9%

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. w…

Fix: 2.16.3 / 3.1.3+
Fix from $1,950 2017-02-20
Mac Os X HIGH 7.8
CVE-2016-7633

An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory Services" component. It allows…

Fix: after 10.12.1
Fix from $1,950 2017-02-20
Iphone Os HIGH 7.8
CVE-2016-7644EPSS 15%

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…

Fix: after 10.12.1
Fix from $1,950 2017-02-20
Watchos HIGH 7.8
CVE-2016-7621

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…

Fix: after 10.12.1
Fix from $1,950 2017-02-20
Iphone Os MEDIUM 6.5
CVE-2016-7591

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…

Fix: after 10.12.1
Fix from $1,600 2017-02-20
Chrome MEDIUM 6.3
CVE-2017-5019

A use after free in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potent…

Fix: after 55.0.2883.87
Fix from $1,600 2017-02-17
Fedora HIGH 7.5
CVE-2017-5357

regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.

Fix: after 1.14
Fix from $1,950 2017-02-17
Mupdf MEDIUM 5.5
CVE-2016-8674

The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application cra…

Fix: after 1.9a
Fix from $1,600 2017-02-15
MySQL HIGH 7.5
CVE-2017-3302

Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10…

Fix: 5.6.21 / 5.7.5+
Fix from $1,950 2017-02-12
Gstreamer HIGH 7.5
CVE-2017-5843

Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functio…

Fix: after 1.10.2
Fix from $1,950 2017-02-09
Linux Kernel HIGH 7.8
CVE-2017-0428

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the cont…

Fix: after 7.1.1
Fix from $1,950 2017-02-08
Linux Kernel HIGH 7.8
CVE-2014-9914

Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges…

Fix: 3.10.45 / 3.12.23+
Fix from $1,950 2017-02-07
Linux Kernel CRITICAL 9.8
CVE-2016-10150EPSS 10%

Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to…

Fix: 4.8.13+
Fix from $2,300 2017-02-06
Bigfix Platform CRITICAL 10.0
CVE-2016-6082

IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker cou…

Patch available
Fix from $2,300 2017-02-01
Libical MEDIUM 5.5
CVE-2016-5823

The icalproperty_new_clone function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics f…

Mitigation only
Fix from $1,600 2017-01-27
Ubuntu Linux MEDIUM 5.5
CVE-2016-5824

libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.

Patch available
Fix from $1,600 2017-01-27
Debian Linux MEDIUM 5.5
CVE-2016-9401

popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.

Fix: 4.4+
Fix from $1,600 2017-01-23
Giflib CRITICAL 9.8
CVE-2016-3177

Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.

Patch available
Fix from $2,300 2017-01-23
Chrome HIGH 8.8
CVE-2016-5203

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker …

Fix: after 54.0.2840.99
Fix from $1,950 2017-01-19
Chrome HIGH 8.8
CVE-2016-5211

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker …

Fix: after 54.0.2840.99
Fix from $1,950 2017-01-19
Chrome HIGH 8.8
CVE-2016-5213

A use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to p…

Fix: after 54.0.2840.99
Fix from $1,950 2017-01-19
Chrome MEDIUM 6.3
CVE-2016-5215

A use after free in webaudio in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacke…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19