Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Acrobat CRITICAL 9.8
CVE-2016-6961EPSS 6%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and A…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Acrobat CRITICAL 9.8
CVE-2016-6953EPSS 6%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and A…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Acrobat CRITICAL 9.8
CVE-2016-6952EPSS 6%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and A…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Acrobat CRITICAL 9.8
CVE-2016-6949EPSS 7%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and A…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Acrobat CRITICAL 9.8
CVE-2016-6946EPSS 6%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and A…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Acrobat CRITICAL 9.8
CVE-2016-6945EPSS 6%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and A…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Acrobat CRITICAL 9.8
CVE-2016-6944EPSS 6%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and A…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Acrobat CRITICAL 9.8
CVE-2016-1091EPSS 6%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and A…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Acrobat CRITICAL 9.8
CVE-2016-1089EPSS 6%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and A…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Digital Editions CRITICAL 9.8
CVE-2016-6980EPSS 5%

Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspecified vectors, a different v…

Fix: after 4.5.1
Fix from $2,300 2016-09-26
Chrome HIGH 8.8
CVE-2016-5171

WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, w…

Fix: after 53.0.2785.101
Fix from $1,950 2016-09-25
Chrome HIGH 8.8
CVE-2016-5170

WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter …

Fix: after 53.0.2785.101
Fix from $1,950 2016-09-25
Firefox CRITICAL 9.8
CVE-2016-5281

Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows re…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5280

Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 4…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5277

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5276

Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x b…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5274

Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thun…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Mupdf MEDIUM 5.5
CVE-2016-6265

Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) vi…

Fix: after 1.9
Fix from $1,600 2016-09-22
Xen MEDIUM 6.7
CVE-2016-7154

Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host cras…

Patch available
Fix from $1,600 2016-09-21
Debian Linux CRITICAL 9.8
CVE-2015-8871

Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact v…

Fix: after 2.1.0
Fix from $2,300 2016-09-21
PHP CRITICAL 9.8
CVE-2016-7413EPSS 7%

Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers…

Fix: after 5.6.25
Fix from $2,300 2016-09-17
Acrobat CRITICAL 9.8
CVE-2016-6938EPSS 8%

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and A…

Fix: after 15.016.20045
Fix from $2,300 2016-09-17
Digital Editions CRITICAL 9.8
CVE-2016-4263EPSS 6%

Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspecified vectors.

Fix: after 4.5.1
Fix from $2,300 2016-09-16
Chrome HIGH 8.8
CVE-2016-5156

extensions/renderer/event_bindings.cc in the event bindings in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux…

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Chrome HIGH 8.8
CVE-2016-5151

PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to …

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Chrome HIGH 8.8
CVE-2016-5150

WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.…

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Debian Linux MEDIUM 5.9
CVE-2016-7180

epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant…

Patch available
Fix from $1,600 2016-09-09
Debian Linux CRITICAL 9.8
CVE-2015-8949

Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call …

Patch available
Fix from $2,300 2016-08-19
Debian Linux CRITICAL 9.8
CVE-2014-9906EPSS 6%

Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary c…

Fix: after 4.028
Fix from $2,300 2016-08-19
Ubuntu Linux HIGH 8.1
CVE-2016-5421EPSS 8%

Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact …

Fix: after 7.50.0
Fix from $1,950 2016-08-10