Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
CRITICAL 9.6 CVE-2020-16018 Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially p… Chrome 87.0.4280.66+ Fix from $2,3002021-01-08 CRITICAL 9.8 CVE-2020-26972 The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a d… Firefox 84.0+ Fix from $2,3002021-01-07 HIGH 8.1 CVE-2020-8265EPSS 9% Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS ena… Node.js 1.0.1.1 / 10.23.1+ Fix from $1,9502021-01-06 CRITICAL 9.8 CVE-2020-35862 An issue was discovered in the bitvec crate before 0.17.4 for Rust. BitVec to BitBox conversion leads to a use-after-free or double free. Bitvec 0.17.4+ Fix from $2,3002020-12-31 CRITICAL 9.8 CVE-2020-35870 An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API use-after-free. Rusqlite 0.23.0+ Fix from $2,3002020-12-31 CRITICAL 9.8 CVE-2020-35873 An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because sessions.rs has a use-after-free. Rusqlite 0.23.0+ Fix from $2,3002020-12-31 HIGH 8.1 CVE-2020-35874 An issue was discovered in the internment crate through 2020-05-28 for Rust. ArcIntern::drop has a race condition and resultant use-after-free. Internment Patch available Fix from $1,9502020-12-31 CRITICAL 9.8 CVE-2020-35876 An issue was discovered in the rio crate through 2020-05-11 for Rust. A struct can be leaked, allowing attackers to obtain sensitive information, cau… Rio after 0.9.3 Fix from $2,3002020-12-31 MEDIUM 6.5 CVE-2018-25001 An issue was discovered in the libpulse-binding crate before 2.5.0 for Rust. proplist::Iterator can cause a use-after-free. Libpulse Binding 2.5.0+ Fix from $1,6002020-12-31 MEDIUM 5.5 CVE-2020-35923 An issue was discovered in the ordered-float crate before 1.1.1 and 2.x before 2.0.1 for Rust. A NotNan value can contain a NaN. Ordered Float 1.1.1 / 2.0.1+ Fix from $1,6002020-12-31 HIGH 7.8 CVE-2020-35906 An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situatio… Futures Task 0.3.6+ Fix from $1,9502020-12-31 MEDIUM 5.5 CVE-2020-35917 An issue was discovered in the pyo3 crate before 0.12.4 for Rust. There is a reference-counting error and use-after-free in From<Py<T>>. Pyo3 0.12.4+ Fix from $1,6002020-12-31 CRITICAL 9.1 CVE-2020-35898 An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more than one mutable reference to t… Actix Utils 2.0.0+ Fix from $2,3002020-12-31 MEDIUM 5.5 CVE-2020-35899 An issue was discovered in the actix-service crate before 1.0.6 for Rust. The Cell implementation allows obtaining more than one mutable reference to… Actix Service 1.0.6+ Fix from $1,6002020-12-31 MEDIUM 5.5 CVE-2020-35900 An issue was discovered in the array-queue crate through 2020-09-26 for Rust. A pop_back() call may lead to a use-after-free. Array Queue after 2020-09-26 Fix from $1,6002020-12-31 HIGH 7.5 CVE-2020-35901 An issue was discovered in the actix-http crate before 2.0.0-alpha.1 for Rust. There is a use-after-free in BodyStream. Actix Http after 1.0.1 Fix from $1,9502020-12-31 CRITICAL 9.8 CVE-2020-35902 An issue was discovered in the actix-codec crate before 0.3.0-beta.1 for Rust. There is a use-after-free in Framed. Actix Codec after 0.2.0 Fix from $2,3002020-12-31 MEDIUM 5.5 CVE-2020-9093 There is a use after free vulnerability in Taurus-AL00A versions 10.0.0.1(C00E1R1P1). A module does not deal with specific message properly, which ma… Taurus Al00a Firmware Mitigation only Fix from $1,6002020-12-29 HIGH 8.8 CVE-2020-13557EPSS 70% A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF do… Foxit Reader No fix yet Fix from $1,9502020-12-22 HIGH 8.8 CVE-2020-13560 A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF do… Foxit Reader No fix yet Fix from $1,9502020-12-22 HIGH 8.8 CVE-2020-13570 A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted PDF document… Foxit Reader No fix yet Fix from $1,9502020-12-22 MEDIUM 6.5 CVE-2020-29483 An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest viol… Debian Linux after 4.14.0 Fix from $1,6002020-12-15 MEDIUM 6.7 CVE-2020-27066 In xfrm6_tunnel_free_spi of net/ipv6/xfrm6_tunnel.c, there is a possible use after free due to improper locking. This could lead to local escalation … Android Patch available Fix from $1,6002020-12-15 MEDIUM 6.4 CVE-2020-27067 In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execu… Android Patch available Fix from $1,6002020-12-15 HIGH 8.8 CVE-2020-29569 An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thr… Linux Kernel 4.2 / 4.4.254+ Fix from $1,9502020-12-15 HIGH 7.8 CVE-2020-27044 In restartWrite of Parcel.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with n… Android Patch available Fix from $1,9502020-12-15 MEDIUM 5.5 CVE-2020-27035 In priorLinearAllocation of C2AllocatorIon.cpp, there is a possible use-after-free due to improper locking. This could lead to local information disc… Android Mitigation only Fix from $1,6002020-12-15 MEDIUM 5.5 CVE-2020-0496 In CPDF_RenderStatus::LoadSMask of cpdf_renderstatus.cpp, there is a possible memory corruption due to a use-after free. This could lead to local inf… Android Mitigation only Fix from $1,6002020-12-15 HIGH 7.0 CVE-2020-0474 In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of pr… Android Patch available Fix from $1,9502020-12-15 MEDIUM 6.7 CVE-2020-0483 In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corruption due to a use after free. This could lead t… Android Patch available Fix from $1,6002020-12-15