Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Traffic Server CRITICAL 9.8
CVE-2026-58185

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 thro…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58164

Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Ser…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Fory HIGH 7.3
CVE-2026-60080

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted …

Fix: 1.4.0+
Fix from $1,950 2026-07-21
HTTP Server HIGH 7.3
CVE-2026-48913

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: …

Fix: 2.4.68+
Fix from $1,950 2026-06-08
HTTP Server CRITICAL 9.8
CVE-2026-29167

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 th…

Fix: 2.4.68+
Fix from $2,300 2026-06-08
Kafka HIGH 8.7
CVE-2026-35554

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. …

Mitigation only
Fix from $1,950 2026-04-07
Arrow HIGH 7.0
CVE-2026-25087

Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading a…

Fix: 23.0.1+
Fix from $1,950 2026-02-17
Nuttx HIGH 8.1
CVE-2025-48769

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer us…

Fix: 12.11.0+
Fix from $1,950 2026-01-01
Xerces C\+\+ CRITICAL 9.8
CVE-2024-23807

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. User…

Fix: 3.2.5+
Fix from $2,300 2024-02-29
Guacamole HIGH 8.1
CVE-2023-30576

Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to ex…

Fix: 1.5.2+
Fix from $1,950 2023-06-07
Subversion HIGH 7.5
CVE-2022-24070EPSS 9%

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use …

Fix: 1.10.8 / 1.14.2+
Fix from $1,950 2022-04-12
Xerces C\+\+ HIGH 8.1
CVE-2018-1311EPSS 10%

The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been …

Fix: 3.2.5+
Fix from $1,950 2019-12-18
HTTP Server CRITICAL 9.1
CVE-2019-10082EPSS 17%

In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during c…

Fix: after 17.3
Fix from $2,300 2019-09-26
HTTP Server MEDIUM 5.3
CVE-2019-0196EPSS 20%

A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access fre…

Fix: after 2.4.38
Fix from $1,600 2019-06-11
HTTP Server HIGH 7.8
CVE-2019-0211 KEVEPSS 65%

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads …

Fix: after 2.4.38
Fix from $1,950 2019-04-08
Mesos HIGH 7.5
CVE-2017-9790

When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1…

Fix: after 1.1.2
Fix from $1,950 2017-09-29
HTTP Server HIGH 7.5
CVE-2017-9798EPSS 95%

Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if http…

Fix: after 2.2.34
Fix from $1,950 2017-09-18
HTTP Server HIGH 7.5
CVE-2017-9789EPSS 10%

When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, r…

Mitigation only
Fix from $1,950 2017-07-13
Openoffice HIGH 9.3
CVE-2010-3451EPSS 10%

Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…

Fix: 3.3.0+
Fix from $1,950 2011-01-28
Openoffice HIGH 9.3
CVE-2010-3452EPSS 10%

Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…

Fix: 3.3.0+
Fix from $1,950 2011-01-28