Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 8.8 CVE-2018-18336 Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a cr… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-18337 Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentiall… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 HIGH 8.8 CVE-2018-18339 Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a … Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 MEDIUM 5.5 CVE-2018-20005 An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc. Fedora No fix yet Fix from $1,6002018-12-10 MEDIUM 6.7 CVE-2018-9517 In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execut… Android Patch available Fix from $1,6002018-12-07 MEDIUM 6.5 CVE-2018-19876 cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leadi… Cairo Patch available Fix from $1,6002018-12-05 HIGH 7.8 CVE-2018-18989 In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the… Cx One after 9.66 Fix from $1,9502018-12-04 HIGH 8.8 CVE-2018-6086 A double-eviction in the Incognito mode cache that lead to a user-after-free in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed… Chrome 66.0.3359.117+ Fix from $1,9502018-12-04 HIGH 8.8 CVE-2018-6087 A use-after-free in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr… Chrome 66.0.3359.117+ Fix from $1,9502018-12-04 HIGH 8.8 CVE-2018-6085 Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a c… Chrome 66.0.3359.117+ Fix from $1,9502018-12-04 HIGH 8.8 CVE-2018-19827 In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that may cause a denial of service… Libsass Mitigation only Fix from $1,9502018-12-03 HIGH 7.8 CVE-2018-19824 In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with ze… Linux Kernel after 4.19.6 Fix from $1,9502018-12-03 MEDIUM 6.5 CVE-2018-16841 Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card auth… Ubuntu Linux 4.7.12 / 4.8.7+ Fix from $1,6002018-11-28 HIGH 7.8 CVE-2018-5856 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, due to a race condition, a Use After Free … Android Patch available Fix from $1,9502018-11-27 HIGH 7.8 CVE-2018-5904 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while list traversal in LPM status driver … Android Patch available Fix from $1,9502018-11-27 HIGH 7.8 CVE-2018-5919 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a use after free issue in WLAN host driver… Android Patch available Fix from $1,9502018-11-27 HIGH 7.8 CVE-2018-11261 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible Use-after-free issue i… Android Patch available Fix from $1,9502018-11-27 HIGH 8.8 CVE-2018-6060 Use after free in WebAudio in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… Chrome 65.0.3325.146+ Fix from $1,9502018-11-14 HIGH 8.8 CVE-2018-6072 An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap… Chrome 65.0.3325.146+ Fix from $1,9502018-11-14 CRITICAL 9.6 CVE-2018-17462 Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML pag… Chrome 70.0.3538.67+ Fix from $2,3002018-11-14 HIGH 8.8 CVE-2018-17465 Incorrect implementation of object trimming in V8 in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit object corr… Chrome 70.0.3538.67+ Fix from $1,9502018-11-14 HIGH 8.8 CVE-2018-17474 Use after free in HTMLImportsController in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit heap corrupt… Chrome 70.0.3538.67+ Fix from $1,9502018-11-14 HIGH 8.8 CVE-2018-8544EPSS 48% A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code … Windows 10 Patch available Fix from $1,9502018-11-14 HIGH 7.8 CVE-2018-19216 Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c. Debian Linux 2.13.02+ Fix from $1,9502018-11-12 HIGH 7.8 CVE-2018-9465 In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privil… Android Patch available Fix from $1,9502018-11-06 HIGH 7.8 CVE-2018-9422 In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional p… Debian Linux Patch available Fix from $1,9502018-11-06 HIGH 7.8 CVE-2018-17909 When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, wh… Cx Supervisor after 3.4.1.0 Fix from $1,9502018-11-05 CRITICAL 9.8 CVE-2018-16840 A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and clea… Curl 7.62.0+ Fix from $2,3002018-10-31 HIGH 8.8 CVE-2018-17621 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is requ… Reader after 9.1.0.5096 Fix from $1,9502018-10-29 HIGH 8.8 CVE-2018-17623 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is requ… Phantompdf after 9.2.0.9297 Fix from $1,9502018-10-29