Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.8 CVE-2020-11120 u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the callback, data buffer may no… Apq8096au Firmware Mitigation only Fix from $1,9502020-09-08 HIGH 7.8 CVE-2019-14117 u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from the list which results in a us… Bitra Firmware Patch available Fix from $1,9502020-09-08 MEDIUM 5.5 CVE-2020-14373 A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to … Enterprise Linux Patch available Fix from $1,6002020-09-03 MEDIUM 5.5 CVE-2020-10720 A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the syst… Linux Kernel 5.2+ Fix from $1,6002020-09-03 MEDIUM 6.8 CVE-2020-5376 Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memor… Inspiron 7347 Bios Mitigation only Fix from $1,6002020-09-02 MEDIUM 6.8 CVE-2020-5378 Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memor… G7 17 7790 Bios 1.13.2+ Fix from $1,6002020-09-02 MEDIUM 5.5 CVE-2020-24240 GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is … Bison Patch available Fix from $1,6002020-08-25 MEDIUM 5.5 CVE-2020-24241 In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c. Netwide Assembler No fix yet Fix from $1,6002020-08-25 HIGH 7.8 CVE-2020-9722EPSS 6% Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-… Acrobat Dc after 20.009.20074 Fix from $1,9502020-08-19 HIGH 7.8 CVE-2020-9715 KEVEPSS 48% Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-… Acrobat Dc after 20.009.20074 Fix from $1,9502020-08-19 MEDIUM 6.7 CVE-2020-9237 Huawei smartphone Taurus-AL00B with versions earlier than 10.1.0.126(C00E125R5P3) have a user after free vulnerability. A module is lack of lock prot… Taurus Al00b Firmware 10.1.0.126+ Fix from $1,6002020-08-17 MEDIUM 5.5 CVE-2020-24349 njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff"… Njs after 0.4.3 Fix from $1,6002020-08-13 HIGH 7.8 CVE-2020-24343 Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c. Mujs after 1.0.7 Fix from $1,9502020-08-13 HIGH 7.8 CVE-2020-24346 njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c. Njs after 0.4.3 Fix from $1,9502020-08-13 HIGH 7.8 CVE-2020-16303 A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker … Debian Linux No fix yet Fix from $1,9502020-08-13 HIGH 7.8 CVE-2020-0242 In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the m… Android Mitigation only Fix from $1,9502020-08-11 HIGH 7.8 CVE-2020-0243 In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privi… Android Mitigation only Fix from $1,9502020-08-11 CRITICAL 9.8 CVE-2020-0252 There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152236803 Android Mitigation only Fix from $2,3002020-08-11 CRITICAL 9.8 CVE-2020-0253 There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152647365 Android No fix yet Fix from $2,3002020-08-11 HIGH 7.8 CVE-2020-7827 DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandle… Daviewindy after 8.98.7 Fix from $1,9502020-07-30 HIGH 7.8 CVE-2020-3701 Use after free issue while processing error notification from camx driver due to not properly releasing the sequence data in Snapdragon Mobile in Sai… Saipan Firmware Mitigation only Fix from $1,9502020-07-30 HIGH 7.8 CVE-2019-10580 When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been already freed in Snapdragon Au… Mdm9607 Firmware Patch available Fix from $1,9502020-07-30 HIGH 7.8 CVE-2019-14037 Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, S… Apq8009 Firmware Patch available Fix from $1,9502020-07-30 CRITICAL 9.8 CVE-2020-3671 Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compute, Snapdragon Consumer IOT, … Apq8009 Firmware Mitigation only Fix from $2,3002020-07-30 MEDIUM 6.4 CVE-2020-15706 GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a fun… Enterprise Linux Atomic Host after 2.04 Fix from $1,6002020-07-29 CRITICAL 9.6 CVE-2020-6509 Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to pot… Chrome 83.0.4103.116+ Fix from $2,3002020-07-22 HIGH 8.8 CVE-2020-6515 Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… Chrome 84.0.4147.89+ Fix from $1,9502020-07-22 HIGH 8.8 CVE-2020-6518 Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools … Chrome 84.0.4147.89+ Fix from $1,9502020-07-22 CRITICAL 9.6 CVE-2020-6505 Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML… Chrome 83.0.4103.106+ Fix from $2,3002020-07-22 HIGH 8.8 CVE-2020-15888 Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer… Lua Patch available Fix from $1,9502020-07-21