Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
MEDIUM 6.7 CVE-2022-20581 In the Pixel camera driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege wit… Android Mitigation only Fix from $1,6002022-12-16 HIGH 7.8 CVE-2022-20561 In TBD of aud_hal_tunnel.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no a… Android Mitigation only Fix from $1,9502022-12-16 HIGH 7.8 CVE-2022-20566 In l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no… Android Patch available Fix from $1,9502022-12-16 HIGH 7.8 CVE-2022-20568 In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no… Android Patch available Fix from $1,9502022-12-16 MEDIUM 6.7 CVE-2022-20571 In extract_metadata of dm-android-verity.c, there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escala… Android Patch available Fix from $1,6002022-12-16 HIGH 7.8 CVE-2022-20540 In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalat… Android Patch available Fix from $1,9502022-12-16 MEDIUM 5.5 CVE-2022-20552 In btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to a use after free. This could lead to local inform… Android Patch available Fix from $1,6002022-12-16 MEDIUM 6.7 CVE-2022-20554 In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege wi… Android Patch available Fix from $1,6002022-12-16 MEDIUM 6.7 CVE-2022-20514 In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possible out o… Android Patch available Fix from $1,6002022-12-16 HIGH 7.8 CVE-2022-20524 In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege wi… Android Patch available Fix from $1,9502022-12-16 HIGH 8.8 CVE-2022-42867EPSS 35% A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and… Safari 9.2 / 13.1+ Fix from $1,9502022-12-15 HIGH 7.8 CVE-2022-4283 A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in… Fedora Mitigation only Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-46342 A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it … Fedora Mitigation only Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-46343 A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after … Fedora Mitigation only Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-4437 Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HT… Chrome 108.0.5359.124+ Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-4438 Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI int… Chrome 108.0.5359.124+ Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-4439 Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI … Chrome 108.0.5359.124+ Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-4440 Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HT… Chrome 108.0.5359.124+ Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-4436 Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted… Chrome 108.0.5359.124+ Fix from $1,9502022-12-14 HIGH 7.8 CVE-2022-44683EPSS 8% Windows Kernel Elevation of Privilege Vulnerability Windows 10 No fix yet Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-41285 A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visua… Jt2go 13.2.0.12 / 13.3.0.8+ Fix from $1,9502022-12-13 MEDIUM 5.5 CVE-2022-20502 In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclos… Android Patch available Fix from $1,6002022-12-13 HIGH 7.8 CVE-2022-25677 Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdrag… Apq8096au Firmware Patch available Fix from $1,9502022-12-13 MEDIUM 5.5 CVE-2022-20496 In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local info… Android Patch available Fix from $1,6002022-12-13 HIGH 8.8 CVE-2022-42716 An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make improper GPU processing operatio… Valhall Gpu Kernel Driver No fix yet Fix from $1,9502022-12-12 HIGH 7.8 CVE-2022-43508 Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by … Cx Programmer after 9.77 Fix from $1,9502022-12-07 MEDIUM 5.5 CVE-2022-42754 In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel. Android Mitigation only Fix from $1,6002022-12-06 HIGH 7.5 CVE-2022-35254 An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R1… Connect Secure 9.1+ Fix from $1,9502022-12-05 MEDIUM 6.5 CVE-2022-42705 A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to … Asterisk 16.29.1 / 18.15.1+ Fix from $1,6002022-12-05 HIGH 7.8 CVE-2022-4292 Use After Free in GitHub repository vim/vim prior to 9.0.0882. Vim 9.0.0882+ Fix from $1,9502022-12-05