Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
365 Apps HIGH 7.8
CVE-2025-62216

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-62213

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
365 Apps HIGH 7.8
CVE-2025-62205

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-11-11
365 Apps HIGH 7.8
CVE-2025-62199

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19426.20044+
Fix from $1,950 2025-11-11
365 Apps HIGH 7.8
CVE-2025-62203

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20068+
Fix from $1,950 2025-11-11
Windows 10 1809 MEDIUM 6.3
CVE-2025-60723

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny …

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,600 2025-11-11
Windows 10 1809 HIGH 7.0
CVE-2025-60716

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Windows 10 1809 HIGH 7.0
CVE-2025-60717

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Windows 10 1809 HIGH 7.8
CVE-2025-60707

Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Windows 10 1809 HIGH 7.0
CVE-2025-59515

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Indesign HIGH 7.8
CVE-2025-61815

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in th…

Fix: 20.5.1+
Fix from $1,950 2025-11-11
Incopy HIGH 7.8
CVE-2025-61817

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Fix: 20.5.1+
Fix from $1,950 2025-11-11
Incopy HIGH 7.8
CVE-2025-61818

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Fix: 20.5.1+
Fix from $1,950 2025-11-11
Indesign HIGH 7.8
CVE-2025-61814

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in th…

Fix: 20.5.1+
Fix from $1,950 2025-11-11
Firefox HIGH 8.8
CVE-2025-13020

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird…

Fix: 140.5.0 / 145.0+
Fix from $1,950 2025-11-11
Firefox HIGH 8.8
CVE-2025-13014

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and…

Fix: 115.30.0 / 140.5.0+
Fix from $1,950 2025-11-11
Openexr HIGH 7.5
CVE-2025-64183

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In v…

Fix: 3.2.5 / 3.3.6+
Fix from $1,950 2025-11-10
Chrome HIGH 7.5
CVE-2025-12437

Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures t…

Fix: 142.0.7444.59+
Fix from $1,950 2025-11-10
Chrome HIGH 8.8
CVE-2025-12438

Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to potentially exploit object corrupt…

Fix: 142.0.7444.59+
Fix from $1,950 2025-11-10
Chrome HIGH 8.8
CVE-2025-11460

Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chro…

Fix: 141.0.7390.65+
Fix from $1,950 2025-11-06
Chrome HIGH 8.8
CVE-2025-11756

Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 141.0.7390.107+
Fix from $1,950 2025-11-06
Safari HIGH 8.8
CVE-2023-43000 KEV

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.…

Fix: 13.5 / 15.8.7+
Fix from $1,950 2025-11-05
Exynos 1480 Firmware MEDIUM 6.5
CVE-2025-54335

An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU Dri…

Mitigation only
Fix from $1,600 2025-11-04
Exynos 1280 Firmware CRITICAL 9.8
CVE-2025-52910

An issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 1480, 2400. A Use-After-Free lea…

Mitigation only
Fix from $2,300 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43478

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 2…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
Safari MEDIUM 6.5
CVE-2025-43457

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1,…

Fix: 26.1+
Fix from $1,600 2025-11-04
Netsurf MEDIUM 6.5
CVE-2025-29699

NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

No fix yet
Fix from $1,600 2025-11-03
Vtk CRITICAL 9.8
CVE-2025-57108

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests …

Fix: after 9.5.0
Fix from $2,300 2025-10-31
Unclassified MEDIUM 6.5
CVE-2025-57109

Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with inva…

Mitigation only
Fix from $1,600 2025-10-30
Unclassified HIGH 7.3
CVE-2025-62229

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification …

Mitigation only
Fix from $1,950 2025-10-30