Vulnerability index

Browse CVEs

171 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Debian Linux HIGH 7.8
CVE-2024-26739

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we'r…

Fix: 5.10.238 / 5.15.182+
Fix from $1,950 2024-04-03
Debian Linux HIGH 7.8
CVE-2023-52572

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix UAF in cifs_demultiplex_thread() There is a UAF when xfstests on cifs…

Fix: 5.4.297 / 5.10.237+
Fix from $1,950 2024-03-02
Debian Linux HIGH 7.0
CVE-2023-6270

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct n…

Fix: 6.9+
Fix from $1,950 2024-01-04
Debian Linux HIGH 7.0
CVE-2023-6932

A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition c…

Fix: 4.14.332 / 4.19.301+
Fix from $1,950 2023-12-19
Debian Linux HIGH 8.8
CVE-2023-6509

Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI i…

Fix: 120.0.6099.62+
Fix from $1,950 2023-12-06
Debian Linux HIGH 8.8
CVE-2023-6510

Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI inter…

Fix: 120.0.6099.62+
Fix from $1,950 2023-12-06
Debian Linux HIGH 8.8
CVE-2023-39928

A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability …

Mitigation only
Fix from $1,950 2023-10-06
Debian Linux MEDIUM 6.6
CVE-2023-5197

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Addition…

Fix: 5.10.198 / 5.15.134+
Fix from $1,600 2023-09-27
Debian Linux CRITICAL 9.8
CVE-2023-39355

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release bran…

Patch available
Fix from $2,300 2023-08-31
Debian Linux HIGH 7.8
CVE-2023-21255

In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege wi…

Patch available
Fix from $1,950 2023-07-13
Debian Linux HIGH 7.8
CVE-2022-42332

x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP)…

Mitigation only
Fix from $1,950 2023-03-21
Debian Linux HIGH 7.0
CVE-2023-0266 KEV

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be u…

Fix: 4.14.303 / 4.19.270+
Fix from $1,950 2023-01-30
Debian Linux HIGH 7.5
CVE-2022-43680

In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memo…

Fix: after 2.4.9
Fix from $1,950 2022-10-24
Debian Linux HIGH 7.8
CVE-2022-20421

In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2022-10-11
Debian Linux HIGH 8.1
CVE-2022-40674

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

Fix: 2.4.9+
Fix from $1,950 2022-09-14
Debian Linux HIGH 7.8
CVE-2022-3134

Use After Free in GitHub repository vim/vim prior to 9.0.0389.

Fix: 9.0.0389+
Fix from $1,950 2022-09-06
Debian Linux HIGH 8.1
CVE-2022-32293

In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading t…

Fix: after 1.41
Fix from $1,950 2022-08-03
Debian Linux HIGH 7.8
CVE-2022-1968

Use After Free in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.5050 / 13.0+
Fix from $1,950 2022-06-02
Debian Linux MEDIUM 5.5
CVE-2022-26291

lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vul…

Patch available
Fix from $1,600 2022-03-28
Debian Linux HIGH 7.5
CVE-2021-3748

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct acc…

Fix: 6.2.0+
Fix from $1,950 2022-03-23
Debian Linux CRITICAL 9.8
CVE-2022-23608

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 16.8.0 / 16.24.1+
Fix from $2,300 2022-02-22
Debian Linux MEDIUM 5.5
CVE-2021-36408

An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265.

No fix yet
Fix from $1,600 2022-01-10
Debian Linux MEDIUM 5.5
CVE-2021-45944

Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).

Fix: after 9.53.3
Fix from $1,600 2022-01-01
Debian Linux HIGH 8.8
CVE-2021-21900

A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dx…

No fix yet
Fix from $1,950 2021-11-19
Debian Linux CRITICAL 9.1
CVE-2021-43400

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu…

Patch available
Fix from $2,300 2021-11-04
Debian Linux MEDIUM 5.5
CVE-2020-21913

International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in t…

Fix: 66.1+
Fix from $1,600 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-36055

XMP Toolkit SDK versions 2020.1 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the con…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux HIGH 8.8
CVE-2020-21688

A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code.

Patch available
Fix from $1,950 2021-08-10
Debian Linux MEDIUM 6.5
CVE-2020-21697

A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service (DOS) via a cr…

Patch available
Fix from $1,600 2021-08-10
Debian Linux MEDIUM 5.5
CVE-2021-27347

Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed …

Patch available
Fix from $1,600 2021-06-10