Vulnerability index

Browse CVEs

682 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper LockingCWE-667 × clear
Ubuntu Linux HIGH 7.5
CVE-2020-24606EPSS 5%

Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a …

Fix: 4.13 / 5.0.4+
Fix from $1,950 2020-08-24
Android HIGH 7.8
CVE-2020-0242

In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the m…

Mitigation only
Fix from $1,950 2020-08-11
Android HIGH 7.8
CVE-2020-0243

In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privi…

Mitigation only
Fix from $1,950 2020-08-11
Galaxy HIGH 7.8
CVE-2020-15529

An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repa…

Mitigation only
Fix from $1,950 2020-07-05
Mdm9607 Firmware HIGH 7.8
CVE-2019-14091

Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consume…

Mitigation only
Fix from $1,950 2020-06-22
Gitea HIGH 7.5
CVE-2020-13246

An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one org…

Fix: after 1.11.5
Fix from $1,950 2020-05-20
Linux Kernel MEDIUM 5.5
CVE-2020-12771

An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation f…

Fix: after 5.6.11
Fix from $1,600 2020-05-09
Linux Kernel HIGH 7.0
CVE-2019-14898

The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive informati…

Patch available
Fix from $1,950 2020-05-08
Janus HIGH 7.5
CVE-2020-10573

An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge.

Fix: after 0.9.1
Fix from $1,950 2020-03-14
Apq8009 Firmware HIGH 8.1
CVE-2019-10494

Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapd…

Patch available
Fix from $1,950 2019-12-12
Debian Linux MEDIUM 6.8
CVE-2019-17343

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect …

Fix: after 4.11.2
Fix from $1,600 2019-10-08
Android MEDIUM 5.5
CVE-2019-9268

In libstagefright, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server w…

Mitigation only
Fix from $1,600 2019-09-27
Android MEDIUM 6.7
CVE-2019-9447

In the Android kernel in the FingerTipS touchscreen driver there is a possible use-after-free due to improper locking. This could lead to a local esc…

Mitigation only
Fix from $1,600 2019-09-06
Android MEDIUM 6.7
CVE-2019-9273

In the Android kernel in the synaptics_dsx_htc touchscreen driver there is a possible use after free due to improper locking. This could lead to loca…

Mitigation only
Fix from $1,600 2019-09-06
Android MEDIUM 6.7
CVE-2019-9275

In the Android kernel in the mnh driver there is a use after free due to improper locking. This could lead to escalation of privilege with System exe…

Mitigation only
Fix from $1,600 2019-09-06
Android HIGH 7.8
CVE-2019-2174

In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper…

Patch available
Fix from $1,950 2019-09-05
Libuci HIGH 7.5
CVE-2019-15513

An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 a…

No fix yet
Fix from $1,950 2019-08-23
Linux Kernel MEDIUM 5.5
CVE-2019-14763

In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock with f_hid.

Fix: 4.16.4+
Fix from $1,600 2019-08-07
Android MEDIUM 5.5
CVE-2019-2119

In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This could lead to local informat…

Mitigation only
Fix from $1,600 2019-07-08
Tomcat HIGH 7.5
CVE-2019-10072EPSS 73%

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.1…

Fix: after 9.0.19
Fix from $1,950 2019-06-21
Android HIGH 7.8
CVE-2019-2025

In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in th…

Mitigation only
Fix from $1,950 2019-06-19
Z4 G4 Workstation Firmware HIGH 7.2
CVE-2019-6321

HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with …

Fix: 1.70 / 1.71+
Fix from $1,950 2019-05-29
Z4 G4 Workstation Firmware MEDIUM 6.8
CVE-2019-6322

HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with …

Fix: 1.70 / 1.71+
Fix from $1,600 2019-05-29
Nx Os MEDIUM 6.4
CVE-2019-1732

A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator…

Fix: 7.0+
Fix from $1,600 2019-05-15
Asa 5500 Firmware MEDIUM 6.7
CVE-2019-1649

A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could al…

Fix: 1.0.18 / 1.1.15+
Fix from $1,600 2019-05-13
Android HIGH 7.8
CVE-2019-2050

In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This could lead to local escalation o…

Mitigation only
Fix from $1,950 2019-05-08
Linux Kernel HIGH 7.0
CVE-2019-11599

The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes whi…

Fix: 3.16.66 / 4.4.183+
Fix from $1,950 2019-04-29
Shopxo CRITICAL 9.8
CVE-2019-5886

An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, wh…

No fix yet
Fix from $2,300 2019-01-10
Aironet Access Points MEDIUM 6.8
CVE-2018-0381

A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device …

Mitigation only
Fix from $1,600 2018-10-17
Secure Firewall Threat Defense MEDIUM 6.8
CVE-2018-15390

A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to caus…

Fix: after 6.2.3.4
Fix from $1,600 2018-10-05