Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome MEDIUM 6.3
CVE-2016-5216

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker …

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.3
CVE-2016-5219

A heap use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Provisioning Services CRITICAL 9.8
CVE-2016-9678

Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $2,300 2017-01-18
Exynos Fimg2d Driver HIGH 7.5
CVE-2016-9279

Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sens…

Mitigation only
Fix from $1,950 2017-01-18
Libical CRITICAL 9.1
CVE-2016-9584

libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file.

Fix: after 2.0
Fix from $2,300 2017-01-18
Debian Linux MEDIUM 5.5
CVE-2016-7906

magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.

Patch available
Fix from $1,600 2017-01-18
Linux Kernel HIGH 7.1
CVE-2017-2584

arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel memory or cause a denial of s…

Fix: after 4.9.3
Fix from $1,950 2017-01-15
Matrixssl HIGH 7.5
CVE-2016-6885

The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base zero val…

Fix: after 3.8.3
Fix from $1,950 2017-01-13
PHP CRITICAL 9.8
CVE-2016-7479EPSS 36%

In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free.…

No fix yet
Fix from $2,300 2017-01-12
Acrobat HIGH 7.8
CVE-2017-2950EPSS 6%

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerabilit…

Fix: after 15.020.20042
Fix from $1,950 2017-01-11
Acrobat HIGH 7.8
CVE-2017-2951EPSS 5%

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerabilit…

Fix: after 15.020.20042
Fix from $1,950 2017-01-11
Acrobat HIGH 7.8
CVE-2017-2955

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerabilit…

Fix: after 15.020.20042
Fix from $1,950 2017-01-11
Acrobat HIGH 7.8
CVE-2017-2956

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerabilit…

Fix: after 15.020.20042
Fix from $1,950 2017-01-11
Acrobat HIGH 7.8
CVE-2017-2957

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerabilit…

Fix: after 15.020.20042
Fix from $1,950 2017-01-11
Acrobat HIGH 7.8
CVE-2017-2958EPSS 10%

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerabilit…

Fix: after 15.020.20042
Fix from $1,950 2017-01-11
Acrobat HIGH 7.8
CVE-2017-2961EPSS 6%

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerabilit…

Fix: after 15.020.20042
Fix from $1,950 2017-01-11
Matrixssl HIGH 7.5
CVE-2016-6892

The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory) via a cra…

Fix: after 3.8.5
Fix from $1,950 2017-01-05
PHP CRITICAL 9.8
CVE-2016-9137

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attacker…

Fix: after 5.6.26
Fix from $2,300 2017-01-04
PHP CRITICAL 9.8
CVE-2016-9138

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denia…

Fix: after 5.6.27
Fix from $2,300 2017-01-04
PHP CRITICAL 9.8
CVE-2016-9936

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) o…

Patch available
Fix from $2,300 2017-01-04
Linux Kernel HIGH 7.0
CVE-2016-10088

The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, wh…

Fix: 3.10.107 / 3.12.70+
Fix from $1,950 2016-12-30
Linux Kernel HIGH 7.8
CVE-2016-9576

The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows l…

Fix: 4.4.38 / 4.8.14+
Fix from $1,950 2016-12-28
Linux Kernel HIGH 7.8
CVE-2016-9794

Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users…

Fix: 3.2.85 / 3.10.105+
Fix from $1,950 2016-12-28
Qemu MEDIUM 5.5
CVE-2016-9923

Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging t…

Fix: after 2.7.1
Fix from $1,600 2016-12-23
Chrome HIGH 8.8
CVE-2016-5183

A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android allows a remote attacker…

Fix: after 53.0.2785.143
Fix from $1,950 2016-12-18
Chrome HIGH 8.8
CVE-2016-5184

PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles in CFFL_For…

Fix: after 53.0.2785.143
Fix from $1,950 2016-12-18
Chrome HIGH 8.8
CVE-2016-5185

Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly allowed reentrance of FrameView::updat…

Fix: after 53.0.2785.143
Fix from $1,950 2016-12-18
Chrome MEDIUM 6.3
CVE-2016-5190

Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles during shutdown, whic…

Fix: after 53.0.2785.143
Fix from $1,600 2016-12-18
Flash Player Desktop Runtime HIGH 8.8
CVE-2016-7892 KEVEPSS 19%

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class.…

Fix: after 23.0.0.207
Fix from $1,950 2016-12-15
Linux Kernel HIGH 7.8
CVE-2016-9120

Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or…

Fix: 3.16.40 / 3.18.51+
Fix from $1,950 2016-12-08