Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Linux Kernel HIGH 7.8
CVE-2015-0568

Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driver for the Linux kernel 3.x, …

Fix: after 3.19.8
Fix from $1,950 2016-08-07
Chrome CRITICAL 9.8
CVE-2016-5142

The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers,…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
PHP CRITICAL 9.8
CVE-2016-5771EPSS 15%

spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage co…

Fix: 5.5.37 / 5.6.23+
Fix from $2,300 2016-08-07
Linux Kernel HIGH 7.3
CVE-2016-3841

The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (us…

Fix: 3.2.75 / 3.12.52+
Fix from $1,950 2016-08-06
Firefox HIGH 8.8
CVE-2016-5264

Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 4…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 8.8
CVE-2016-5259

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remo…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Linux HIGH 8.8
CVE-2016-5258

Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to e…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 8.8
CVE-2016-5255

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbi…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox CRITICAL 9.8
CVE-2016-5254

Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attack…

Fix: after 47.0.1
Fix from $2,300 2016-08-05
Chrome HIGH 8.8
CVE-2016-5136

Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome before 52.0.2743.82 allows r…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Chrome HIGH 8.8
CVE-2016-5131

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of ser…

Fix: 10.0 / 52.0.2743.82+
Fix from $1,950 2016-07-23
Chrome HIGH 7.5
CVE-2016-5127

Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Google Chrome before 52.0.2743.82, allows remote att…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Chrome HIGH 8.8
CVE-2016-1708

The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider o…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Mac Os X HIGH 7.8
CVE-2016-4625

Use-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspecified vectors.

Fix: after 10.11.5
Fix from $1,950 2016-07-22
Iphone Os HIGH 7.8
CVE-2016-1863

The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause…

Fix: 2.2.2 / 9.2.2+
Fix from $1,950 2016-07-22
Gimp HIGH 7.8
CVE-2016-4994

Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (progr…

Fix: 2.8.18+
Fix from $1,950 2016-07-12
Python MEDIUM 6.5
CVE-2016-3189EPSS 16%

Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, re…

Fix: 3.7.13 / 3.8.13+
Fix from $1,600 2016-06-30
Flash Player CRITICAL 9.8
CVE-2016-4121EPSS 10%

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.…

Fix: after 21.0.0.241
Fix from $2,300 2016-06-16
Enterprise Linux HIGH 7.8
CVE-2016-4805

Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memor…

Fix: 3.2.80 / 3.10.102+
Fix from $1,950 2016-05-23
Ubuntu Linux MEDIUM 5.5
CVE-2016-1837EPSS 8%

Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in …

Patch available
Fix from $1,600 2016-05-20
Ubuntu Linux MEDIUM 5.5
CVE-2016-1836EPSS 8%

Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, t…

Patch available
Fix from $1,600 2016-05-20
Tvos HIGH 7.8
CVE-2016-1819EPSS 10%

Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, an…

Fix: 2.2.1 / 9.2.1+
Fix from $1,950 2016-05-20
Flash Player HIGH 8.8
CVE-2015-8823EPSS 6%

Use-after-free vulnerability in the TextField object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Wi…

Fix: after 19.0.0.245
Fix from $1,950 2016-04-22
Openstack HIGH 8.8
CVE-2016-1568

Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service…

Fix: after 2.5.1.1
Fix from $1,950 2016-04-12
Flash Player HIGH 8.8
CVE-2016-1031EPSS 5%

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.…

Fix: after 21.0.0.197
Fix from $1,950 2016-04-09
Flash Player HIGH 8.8
CVE-2016-1017EPSS 6%

Use-after-free vulnerability in the LoadVars.decode function in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windo…

Fix: after 21.0.0.197
Fix from $1,950 2016-04-09
Flash Player HIGH 8.8
CVE-2016-1016EPSS 6%

Use-after-free vulnerability in the Transform object implementation in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 o…

Fix: after 21.0.0.197
Fix from $1,950 2016-04-09
Flash Player HIGH 8.8
CVE-2016-1013EPSS 23%

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.…

Fix: after 21.0.0.197
Fix from $1,950 2016-04-09
Flash Player HIGH 8.8
CVE-2016-1011EPSS 26%

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.…

Fix: after 21.0.0.197
Fix from $1,950 2016-04-09
Iphone Os HIGH 7.8
CVE-2016-1750

Use-after-free vulnerability in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to …

Fix: 2.2 / 9.2+
Fix from $1,950 2016-03-24