Vulnerability index

Browse CVEs

7,925 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.8 CVE-2026-53009 In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the erro… Linux Kernel 7.0.10+ Fix from $1,9502026-06-24 CRITICAL 9.8 CVE-2026-53010 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durable reconnect In smb2_open, t… Linux Kernel 6.7 / 6.18.33+ Fix from $2,3002026-06-24 HIGH 7.8 CVE-2026-53011 In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: fix use-after-free in advance_sched() on schedule switch In … Linux Kernel 5.10.258 / 5.15.209+ Fix from $1,9502026-06-24 HIGH 7.8 CVE-2026-53005 In the Linux kernel, the following vulnerability has been resolved: af_unix: Drop all SCM attributes for SOCKMAP. SOCKMAP can hide inflight fd from… Linux Kernel 7.0.10+ Fix from $1,9502026-06-24 CRITICAL 9.8 CVE-2026-53006 In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull… Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-06-24 HIGH 7.8 CVE-2026-52976 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() Two error handling is… Linux Kernel 6.12.91 / 6.18.33+ Fix from $1,9502026-06-24 CRITICAL 9.8 CVE-2026-52982 In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a… Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-06-24 HIGH 7.8 CVE-2026-52971 In the Linux kernel, the following vulnerability has been resolved: net: ena: PHC: Fix potential use-after-free in get_timestamp Move the phc->acti… Linux Kernel 6.18.33 / 7.0.10+ Fix from $1,9502026-06-24 HIGH 7.8 CVE-2026-52973 In the Linux kernel, the following vulnerability has been resolved: futex: Drop CLONE_THREAD requirement for private default hash alloc Currently n… Linux Kernel 6.18.33 / 7.0.10+ Fix from $1,9502026-06-24 HIGH 7.8 CVE-2026-52950 In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: fix UAF with retry loop Retry doesn't work here, since bo will … Linux Kernel 6.18.33 / 7.0.10+ Fix from $1,9502026-06-24 HIGH 7.8 CVE-2026-52951 In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: handle empty bo and UAF races There look to be some nasty races… Linux Kernel 6.12.91 / 6.18.33+ Fix from $1,9502026-06-24 HIGH 7.8 CVE-2026-52947 In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove In qrt… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-06-24 HIGH 7.8 CVE-2026-52943 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_in… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-06-24 CRITICAL 9.8 CVE-2026-52924 In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only… Linux Kernel 5.10.259 / 5.15.210+ Fix from $2,3002026-06-24 HIGH 7.8 CVE-2026-52912 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewri… Linux Kernel 5.10.259 / 5.15.209+ Fix from $1,9502026-06-24 MEDIUM 6.5 CVE-2026-56113 dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash… Dhcpcd after 10.3.2 Fix from $1,6002026-06-23 MEDIUM 5.5 CVE-2026-56117 dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that… Dhcpcd after 10.3.2 Fix from $1,6002026-06-23 CRITICAL 9.8 CVE-2026-6653 Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service … Libxml2 after 2.11.0 Fix from $2,3002026-06-22 MEDIUM 5.9 CVE-2026-56412 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within… Libexpat 2.8.2+ Fix from $1,6002026-06-21 MEDIUM 6.5 CVE-2026-12706 A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed bu… Mitigation only Fix from $1,6002026-06-19 MEDIUM 5.6 CVE-2026-11941 Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_nex… Mitigation only Fix from $1,6002026-06-19 HIGH 7.7 CVE-2026-34192 Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading to UAF of GPU page tables. … Mitigation only Fix from $1,9502026-06-19 HIGH 7.7 CVE-2026-41156 Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources creating a write use af… Mitigation only Fix from $1,9502026-06-19 MEDIUM 5.0 CVE-2026-11791 A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information… Directory Server Mitigation only Fix from $1,6002026-06-18 CRITICAL 9.8 CVE-2026-9158 In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling poin… 4diac Forte after 3.1.0 Fix from $2,3002026-06-18 HIGH 8.1 CVE-2026-42530 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote … Nginx Gateway Fabric 1.31.2 / 2.6.4+ Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-12462 Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execute arbitr… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 8.3 CVE-2026-12464 Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially … Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 8.3 CVE-2026-12467 Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potential… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-12455 Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17