Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
MEDIUM 5.3 CVE-2021-42779 A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid. Fedora 0.22.0+ Fix from $1,6002022-04-18 HIGH 7.5 CVE-2021-44497 An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, can cause the bounds of a for loop to b… Gt.m after 7.0-000 Fix from $1,9502022-04-15 HIGH 8.8 CVE-2022-28042 stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode. Fedora Patch available Fix from $1,9502022-04-15 CRITICAL 9.8 CVE-2022-27007 nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_func… Njs Patch available Fix from $2,3002022-04-14 HIGH 7.5 CVE-2022-27455 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c. MariaDB 10.4.25 / 10.5.16+ Fix from $1,9502022-04-14 HIGH 7.5 CVE-2022-27456 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc. MariaDB 10.3.35 / 10.4.25+ Fix from $1,9502022-04-14 HIGH 7.5 CVE-2022-27457 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c. MariaDB 10.4.25 / 10.5.16+ Fix from $1,9502022-04-14 HIGH 7.5 CVE-2022-27447 MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h. MariaDB 10.3.35 / 10.4.25+ Fix from $1,9502022-04-14 MEDIUM 6.3 CVE-2022-1280 A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows… Linux Kernel after 5.17.4 Fix from $1,6002022-04-13 HIGH 7.5 CVE-2022-27376 MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially c… MariaDB 10.3.35 / 10.4.25+ Fix from $1,9502022-04-12 HIGH 7.5 CVE-2022-27377 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via special… MariaDB 10.2.44 / 10.3.35+ Fix from $1,9502022-04-12 HIGH 7.5 CVE-2022-27383 MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially craf… MariaDB 10.2.44 / 10.3.35+ Fix from $1,9502022-04-12 HIGH 7.5 CVE-2022-24070EPSS 9% Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use … Subversion 1.10.8 / 1.14.2+ Fix from $1,9502022-04-12 MEDIUM 5.5 CVE-2021-39800 In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosur… Android Patch available Fix from $1,6002022-04-12 HIGH 7.8 CVE-2021-39801 In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no add… Android Patch available Fix from $1,9502022-04-12 MEDIUM 6.5 CVE-2021-39803 In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with… Android Patch available Fix from $1,6002022-04-12 HIGH 7.8 CVE-2021-39812 In TBD of TBD, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with no additional ex… Android Patch available Fix from $1,9502022-04-12 HIGH 7.8 CVE-2021-0707 In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with… Android Patch available Fix from $1,9502022-04-12 HIGH 7.0 CVE-2022-27834 Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious… Android Mitigation only Fix from $1,9502022-04-11 HIGH 7.8 CVE-2022-27528 A maliciously crafted DWFX and SKP files in Autodesk Navisworks 2022 can be used to trigger use-after-free vulnerability. Exploitation of this vulner… Navisworks 2022.2+ Fix from $1,9502022-04-11 HIGH 7.8 CVE-2022-25789 A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploit… Advance Steel 2019.1.4 / 2020.1.5+ Fix from $1,9502022-04-11 MEDIUM 6.5 CVE-2022-20052 In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privile… Android Mitigation only Fix from $1,6002022-04-11 MEDIUM 6.7 CVE-2022-20062 In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privile… Android Mitigation only Fix from $1,6002022-04-11 HIGH 7.8 CVE-2022-28893 The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. Linux Kernel 5.4.196 / 5.10.117+ Fix from $1,9502022-04-11 MEDIUM 5.5 CVE-2022-1284 heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service. Radare2 5.6.8+ Fix from $1,6002022-04-08 MEDIUM 5.5 CVE-2022-27147 GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_tag. Gpac 2.0.0+ Fix from $1,6002022-04-08 HIGH 8.8 CVE-2021-41715 libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379. Libsixel No fix yet Fix from $1,9502022-04-08 HIGH 8.8 CVE-2022-27046 libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388. Libsixel No fix yet Fix from $1,9502022-04-08 CRITICAL 9.8 CVE-2022-1212 Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. Mruby after 3.0.0 Fix from $2,3002022-04-05 HIGH 8.8 CVE-2022-0805 Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user i… Chrome 99.0.4844.51+ Fix from $1,9502022-04-05