Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 8.8 CVE-2022-2742 Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage … Chrome 104.0.5112.79+ Fix from $1,9502023-01-02 HIGH 7.5 CVE-2022-3842EPSS 18% Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentiall… Chrome 105.0.5195.125+ Fix from $1,9502023-01-02 MEDIUM 6.1 CVE-2022-3863 Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a craf… Chrome 100.0.4896.75+ Fix from $1,6002023-01-02 HIGH 8.8 CVE-2019-25085 A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gv… Gvariant Database 2019-06-27+ Fix from $1,9502022-12-26 MEDIUM 5.5 CVE-2022-47946 An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to cras… Linux Kernel 5.10.155+ Fix from $1,6002022-12-23 CRITICAL 9.8 CVE-2022-47939EPSS 46% An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_… Linux Kernel 5.15.61 / 5.18.18+ Fix from $2,3002022-12-23 MEDIUM 6.5 CVE-2022-46880 A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on De… Firefox 102.6 / 105.0+ Fix from $1,6002022-12-22 CRITICAL 9.8 CVE-2022-46882 A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6… Firefox 102.6 / 107.0+ Fix from $2,3002022-12-22 CRITICAL 9.8 CVE-2022-45406 If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a Base… Firefox 102.5 / 107.0+ Fix from $2,3002022-12-22 HIGH 7.5 CVE-2022-45407 If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exp… Firefox 107.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-45409 The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, lead… Firefox 102.5 / 107.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-45405 Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable cr… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-40960 Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash… Firefox 102.3 / 105.0+ Fix from $1,6002022-12-22 HIGH 7.5 CVE-2022-38476 A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock prot… Firefox Esr 102.2+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-34484 The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and… Firefox 91.11 / 102.0+ Fix from $1,9502022-12-22 CRITICAL 9.8 CVE-2022-34470 Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR… Firefox 91.11 / 102.0+ Fix from $2,3002022-12-22 CRITICAL 9.8 CVE-2022-31747 Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox … Firefox 91.10 / 101+ Fix from $2,3002022-12-22 MEDIUM 6.5 CVE-2022-28282 By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution a… Firefox 91.8 / 99.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-26485 KEVEPSS 14% Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing thi… Firefox 91.6.1 / 91.6.2+ Fix from $1,9502022-12-22 CRITICAL 9.6 CVE-2022-26486 KEV An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in th… Firefox 91.6.1 / 91.6.2+ Fix from $2,3002022-12-22 MEDIUM 6.5 CVE-2022-26385 In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free causing a po… Firefox 98.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-26381 An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerabili… Firefox 91.7 / 98.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-22740 Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a pote… Firefox 91.5 / 96.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-1097 <code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use… Firefox 91.8 / 99.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-1196 After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. Th… Firefox Esr 91.8+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2021-4128 When transitioning in and out of fullscreen mode, a graphics object was not correctly protected; resulting in memory corruption and a potentially exp… Firefox 95.0+ Fix from $1,6002022-12-22 HIGH 7.8 CVE-2022-46282 Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially cra… Cx Drive after 3.00 Fix from $1,9502022-12-21 HIGH 7.5 CVE-2022-46311 The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity. Harmonyos 2.0+ Fix from $1,9502022-12-20 CRITICAL 9.8 CVE-2021-33640 After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use poin… Fedora Mitigation only Fix from $2,3002022-12-19 MEDIUM 6.7 CVE-2022-42520 In ServiceInterface::HandleRequest of serviceinterface.cpp, there is a possible use after free. This could lead to local escalation of privilege with… Android Mitigation only Fix from $1,6002022-12-16