Vulnerability index

Browse CVEs

7,925 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.8 CVE-2026-12449 Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation vi… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 8.3 CVE-2026-12451 Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to p… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-12452 Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via … Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-12439 Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 CRITICAL 9.6 CVE-2026-12440 Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox e… Chrome 149.0.7827.155+ Fix from $2,3002026-06-17 HIGH 8.8 CVE-2026-12441 Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-12442 Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTM… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-12443 Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML … Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-12445 Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to po… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 8.3 CVE-2026-12437 Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to … Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 7.8 CVE-2026-0143 In lwis_device_external_event_emit of lwis_event.c, there is a possible memory corruption due to a use after free. This could lead to local escalatio… Android Mitigation only Fix from $1,9502026-06-16 HIGH 7.8 CVE-2026-0137 In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to lo… Android Mitigation only Fix from $1,9502026-06-16 HIGH 7.0 CVE-2026-0125 In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wi… Android Mitigation only Fix from $1,9502026-06-16 HIGH 7.5 CVE-2026-10638 subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_req… Zephyr 4.5.0+ Fix from $1,9502026-06-16 HIGH 7.1 CVE-2026-10640 Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-interf… Zephyr 4.5.0+ Fix from $1,9502026-06-16 HIGH 7.1 CVE-2026-10637 subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. Per the network … Zephyr 4.5.0+ Fix from $1,9502026-06-16 MEDIUM 5.3 CVE-2026-12329 Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. Firefox 140.12.0+ Fix from $1,6002026-06-16 HIGH 7.5 CVE-2026-12314 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. Firefox 140.12.0 / 152.0.0+ Fix from $1,9502026-06-16 HIGH 7.5 CVE-2026-12310 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. Firefox 140.12.0 / 152.0.0+ Fix from $1,9502026-06-16 MEDIUM 5.4 CVE-2026-12298 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. Firefox 140.12.0 / 152.0+ Fix from $1,6002026-06-16 HIGH 8.8 CVE-2026-12291 Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 15… Firefox 115.37.0 / 140.12.0+ Fix from $1,9502026-06-16 CRITICAL 9.8 CVE-2026-12293 Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. Firefox 152.0.0+ Fix from $2,3002026-06-16 MEDIUM 6.3 CVE-2026-10635 On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domai… Zephyr Patch available Fix from $1,6002026-06-16 MEDIUM 5.5 CVE-2025-55650 A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Servic… Gpac 26.02.0+ Fix from $1,6002026-06-15 MEDIUM 5.5 CVE-2025-55644 A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Servic… Gpac 26.02.0+ Fix from $1,6002026-06-15 HIGH 7.3 CVE-2026-6040 A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not chec… Mitigation only Fix from $1,9502026-06-15 MEDIUM 5.3 CVE-2026-10634 Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE … Zephyr 4.5.0+ Fix from $1,6002026-06-15 HIGH 7.8 CVE-2026-41158 Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages. Physical memory alloc… Mitigation only Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-11933 A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authe… MongoDB 4.4.31 / 5.0.34+ Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-12035 Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a cr… Chrome 149.0.7827.115+ Fix from $1,9502026-06-11