Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
PHP HIGH 7.5
CVE-2015-1351EPSS 9%

Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote a…

Fix: 5.5.24 / 5.6.8+
Fix from $1,950 2015-03-30
Chrome HIGH 7.5
CVE-2015-1209

Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implemen…

Fix: 40.0.2214.109 / 40.0.2214.111+
Fix from $1,950 2015-02-06
Flash Player CRITICAL 9.8
CVE-2015-0313 KEVEPSS 96%

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.…

Fix: 11.2.202.442 / 13.0.0.269+
Fix from $2,300 2015-02-02
Flash Player HIGH 8.8
CVE-2014-8439 KEVEPSS 20%

Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.…

Fix: 15.0.0.302+
Fix from $1,950 2014-11-25
Chrome HIGH 7.5
CVE-2014-3190

Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, a…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Chrome HIGH 7.5
CVE-2014-3191

Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibl…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-3192

Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation …

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-3193

The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to c…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-3194

Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of ser…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Firefox HIGH 10.0
CVE-2014-1563EPSS 6%

Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thun…

Fix: after 31.1.0
Fix from $1,950 2014-09-03
Windows Media Center MEDIUM 6.8
CVE-2014-4060EPSS 23%

Use-after-free vulnerability in MCPlayer.dll in Microsoft Windows Media Center TV Pack for Windows Vista, Windows 7 SP1, and Windows Media Center for…

Patch available
Fix from $1,600 2014-08-12
Linux Kernel MEDIUM 5.5
CVE-2014-0203

The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of cert…

Fix: 2.6.33+
Fix from $1,600 2014-06-23
Firefox HIGH 8.8
CVE-2014-1531EPSS 6%

Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.…

Fix: 24.5 / 29.0+
Fix from $1,950 2014-04-30
Firefox CRITICAL 9.8
CVE-2014-1532

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x…

Fix: 24.5 / 29.0+
Fix from $2,300 2014-04-30
Firefox HIGH 9.3
CVE-2014-1525

The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection fo…

Fix: 2.26 / 29.0+
Fix from $1,950 2014-04-30
Internet Explorer CRITICAL 9.8
CVE-2014-1776 KEVEPSS 88%

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servi…

Patch available
Fix from $2,300 2014-04-27
Chrome HIGH 7.5
CVE-2014-1732

Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and bef…

Fix: 34.0.1847.131 / 34.0.1847.132+
Fix from $1,950 2014-04-26
Linux Kernel MEDIUM 6.9
CVE-2014-2851

Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service…

Fix: 3.2.60 / 3.4.92+
Fix from $1,600 2014-04-14
Firefox HIGH 10.0
CVE-2014-1512EPSS 31%

Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbi…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Chrome HIGH 7.5
CVE-2014-1713

Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome …

Fix: 33.0.1750.152 / 33.0.1750.154+
Fix from $1,950 2014-03-16
Linux Kernel HIGH 9.3
CVE-2014-0100

Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a den…

Fix: 3.10.37 / 3.12.18+
Fix from $1,950 2014-03-11
Internet Explorer HIGH 8.8
CVE-2014-0322 KEVEPSS 85%

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted …

Patch available
Fix from $1,950 2014-02-14
Firefox CRITICAL 9.8
CVE-2014-1486EPSS 7%

Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, a…

Fix: 24.3 / 27.0+
Fix from $2,300 2014-02-06
Chrome HIGH 7.5
CVE-2013-6641

Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in G…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,950 2014-01-16
Chrome HIGH 7.5
CVE-2013-6644

Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allow attackers to…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,950 2014-01-16
Chrome MEDIUM 6.8
CVE-2013-6645

Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_contents/web_contents_view_aura.cc in Google Chrom…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,600 2014-01-16
Chrome HIGH 7.5
CVE-2013-6646

Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X an…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,950 2014-01-16
Acrobat HIGH 8.8
CVE-2014-0496 KEVEPSS 40%

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execu…

Fix: 10.1.9 / 11.0.6+
Fix from $1,950 2014-01-15
Firefox CRITICAL 9.8
CVE-2013-5618EPSS 10%

Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox …

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-5613EPSS 9%

Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderb…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11