Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.8 CVE-2025-62216 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-62213 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-62205 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-62199 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19426.20044+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-62203 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20068+ Fix from $1,9502025-11-11 MEDIUM 6.3 CVE-2025-60723 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny … Windows 10 1809 10.0.17763.8027 / 10.0.19044.6575+ Fix from $1,6002025-11-11 HIGH 7.0 CVE-2025-60716 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8027 / 10.0.19044.6575+ Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-60717 Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8027 / 10.0.19044.6575+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-60707 Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8027 / 10.0.19044.6575+ Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-59515 Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8027 / 10.0.19044.6575+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-61815 InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in th… Indesign 20.5.1+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-61817 InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context … Incopy 20.5.1+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-61818 InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context … Incopy 20.5.1+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-61814 InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in th… Indesign 20.5.1+ Fix from $1,9502025-11-11 HIGH 8.8 CVE-2025-13020 Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird… Firefox 140.5.0 / 145.0+ Fix from $1,9502025-11-11 HIGH 8.8 CVE-2025-13014 Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and… Firefox 115.30.0 / 140.5.0+ Fix from $1,9502025-11-11 HIGH 7.5 CVE-2025-64183 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In v… Openexr 3.2.5 / 3.3.6+ Fix from $1,9502025-11-10 HIGH 7.5 CVE-2025-12437 Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures t… Chrome 142.0.7444.59+ Fix from $1,9502025-11-10 HIGH 8.8 CVE-2025-12438 Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to potentially exploit object corrupt… Chrome 142.0.7444.59+ Fix from $1,9502025-11-10 HIGH 8.8 CVE-2025-11460 Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chro… Chrome 141.0.7390.65+ Fix from $1,9502025-11-06 HIGH 8.8 CVE-2025-11756 Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potent… Chrome 141.0.7390.107+ Fix from $1,9502025-11-06 HIGH 8.8 CVE-2023-43000 KEV A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.… Safari 13.5 / 15.8.7+ Fix from $1,9502025-11-05 MEDIUM 6.5 CVE-2025-54335 An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU Dri… Exynos 1480 Firmware Mitigation only Fix from $1,6002025-11-04 CRITICAL 9.8 CVE-2025-52910 An issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 1480, 2400. A Use-After-Free lea… Exynos 1280 Firmware Mitigation only Fix from $2,3002025-11-04 MEDIUM 5.5 CVE-2025-43478 A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 2… macOS 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04 MEDIUM 6.5 CVE-2025-43457 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1,… Safari 26.1+ Fix from $1,6002025-11-04 MEDIUM 6.5 CVE-2025-29699 NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function. Netsurf No fix yet Fix from $1,6002025-11-03 CRITICAL 9.8 CVE-2025-57108 Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests … Vtk after 9.5.0 Fix from $2,3002025-10-31 MEDIUM 6.5 CVE-2025-57109 Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with inva… Mitigation only Fix from $1,6002025-10-30 HIGH 7.3 CVE-2025-62229 A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification … Mitigation only Fix from $1,9502025-10-30