Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.8 CVE-2023-52438 In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used dur… Linux Kernel 5.4.268 / 5.10.209+ Fix from $1,9502024-02-20 CRITICAL 9.8 CVE-2024-23310 A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A spe… Fedora No fix yet Fix from $2,3002024-02-20 CRITICAL 9.1 CVE-2024-25198 Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2… Nav2 after 1.1.17 Fix from $2,3002024-02-20 HIGH 8.1 CVE-2024-25199 Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versio… Nav2 after 1.1.17 Fix from $1,9502024-02-20 CRITICAL 9.8 CVE-2024-24793 A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM f… Libdicom No fix yet Fix from $2,3002024-02-20 CRITICAL 9.8 CVE-2024-24794 A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM f… Libdicom No fix yet Fix from $2,3002024-02-20 HIGH 7.8 CVE-2023-21165 In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation… Android Patch available Fix from $1,9502024-02-16 HIGH 7.8 CVE-2023-40107 In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with … Android Patch available Fix from $1,9502024-02-15 HIGH 7.8 CVE-2023-40114 In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalation of p… Android Patch available Fix from $1,9502024-02-15 HIGH 7.8 CVE-2023-40115 In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with… Android Patch available Fix from $1,9502024-02-15 HIGH 7.8 CVE-2023-40100 In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of … Android Patch available Fix from $1,9502024-02-15 HIGH 7.8 CVE-2024-20729 Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code exe… Acrobat Dc 20.005.30574 / 23.008.20533+ Fix from $1,9502024-02-15 HIGH 7.8 CVE-2024-20731 Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code exe… Acrobat Dc 20.005.30574 / 23.008.20533+ Fix from $1,9502024-02-15 MEDIUM 5.5 CVE-2024-20734 Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensit… Acrobat Dc 20.005.30574 / 23.008.20533+ Fix from $1,6002024-02-15 HIGH 7.7 CVE-2022-23090 The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case. An attacker may cause th… FreeBSD Mitigation only Fix from $1,9502024-02-15 HIGH 7.5 CVE-2024-24990 When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note:… Nginx Open Source 1.25.4+ Fix from $1,9502024-02-14 HIGH 7.8 CVE-2024-21384 Microsoft Office OneNote Remote Code Execution Vulnerability 365 Apps Patch available Fix from $1,9502024-02-13 HIGH 8.8 CVE-2024-21375 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20469 / 10.0.14393.6709+ Fix from $1,9502024-02-13 MEDIUM 6.4 CVE-2024-21339 Windows USB Generic Parent Driver Remote Code Execution Vulnerability Windows 10 1809 10.0.17763.5458 / 10.0.19044.4046+ Fix from $1,6002024-02-13 HIGH 8.1 CVE-2024-25110EPSS 7% The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-aft… Azure Uamqp 2024-02-01+ Fix from $1,9502024-02-12 HIGH 7.5 CVE-2024-23322 Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when … Envoy 1.26.7 / 1.27.3+ Fix from $1,9502024-02-09 HIGH 7.8 CVE-2024-25443 An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a … Hugin No fix yet Fix from $1,9502024-02-09 CRITICAL 9.8 CVE-2024-24189 Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c. Jsish Mitigation only Fix from $2,3002024-02-07 CRITICAL 9.8 CVE-2024-1284 Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… Chrome 121.0.6167.160+ Fix from $2,3002024-02-07 HIGH 7.5 CVE-2024-24260 media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subscribe.c. Media Server No fix yet Fix from $1,9502024-02-05 HIGH 7.5 CVE-2024-24262 media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transaction.c. Media Server No fix yet Fix from $1,9502024-02-05 HIGH 7.5 CVE-2024-24263 Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/resp… Lotos Webserver No fix yet Fix from $1,9502024-02-05 HIGH 7.5 CVE-2024-24266 gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c. Gpac No fix yet Fix from $1,9502024-02-05 HIGH 7.0 CVE-2023-5249 Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make impro… Bifrost Gpu Kernel Driver Mitigation only Fix from $1,9502024-02-05 CRITICAL 9.8 CVE-2020-36773 Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single characte… Ghostscript Patch available Fix from $2,3002024-02-04