Vulnerability index

Browse CVEs

171 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Debian Linux HIGH 7.8
CVE-2021-3516

There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trig…

Fix: 2.9.11+
Fix from $1,950 2021-06-01
Debian Linux HIGH 8.8
CVE-2021-3518

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with l…

Fix: 2.9.11+
Fix from $1,950 2021-05-18
Debian Linux CRITICAL 9.8
CVE-2021-20204

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This …

Mitigation only
Fix from $2,300 2021-05-06
Debian Linux MEDIUM 5.5
CVE-2021-21417

fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be tr…

Fix: 2.1.8+
Fix from $1,600 2021-04-29
Debian Linux HIGH 7.8
CVE-2021-3497

GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.

Fix: 1.18.4+
Fix from $1,950 2021-04-19
Debian Linux MEDIUM 6.5
CVE-2020-29483

An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest viol…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux HIGH 7.5
CVE-2020-8231

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

Fix: 1.0.1.1 / 8.2.12+
Fix from $1,950 2020-12-14
Debian Linux HIGH 8.0
CVE-2019-14586

Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or d…

Mitigation only
Fix from $1,950 2020-11-23
Debian Linux HIGH 7.8
CVE-2020-0423

In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in t…

Mitigation only
Fix from $1,950 2020-10-14
Debian Linux MEDIUM 5.5
CVE-2020-0427

In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no …

Patch available
Fix from $1,600 2020-09-17
Debian Linux MEDIUM 6.5
CVE-2020-25269

An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with …

Fix: 2.0.29 / 3.6.0+
Fix from $1,600 2020-09-11
Debian Linux HIGH 7.8
CVE-2020-16303

A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker …

No fix yet
Fix from $1,950 2020-08-13
Debian Linux MEDIUM 5.5
CVE-2020-15569

PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destructor.

Fix: after 1.02.00
Fix from $1,600 2020-07-06
Debian Linux MEDIUM 6.5
CVE-2020-15389

jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory…

Fix: after 2.3.1
Fix from $1,600 2020-06-29
Debian Linux HIGH 7.8
CVE-2018-10756

Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly exec…

Fix: 3.00+
Fix from $1,950 2020-05-15
Debian Linux HIGH 8.8
CVE-2020-9273EPSS 12%

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool i…

Fix: 3.0+
Fix from $1,950 2020-02-20
Debian Linux CRITICAL 9.8
CVE-2019-19950

In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

Patch available
Fix from $2,300 2019-12-24
Debian Linux MEDIUM 5.5
CVE-2015-1606

The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid re…

Fix: 2.1.2+
Fix from $1,600 2019-11-20
Debian Linux HIGH 7.5
CVE-2019-18408

archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED si…

Fix: 3.4.0+
Fix from $1,950 2019-10-24
Debian Linux HIGH 7.8
CVE-2019-2215 KEVEPSS 44%

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit thi…

Patch available
Fix from $1,950 2019-10-11
Debian Linux HIGH 7.8
CVE-2019-14533

The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14777

The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14778

The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

Patch available
Fix from $1,950 2019-08-29
Cron MEDIUM 5.5
CVE-2019-9706

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_…

Patch available
Fix from $1,600 2019-03-12
Debian Linux MEDIUM 5.3
CVE-2019-7317EPSS 9%

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Fix: 8.0.23+
Fix from $1,600 2019-02-04
Debian Linux CRITICAL 9.8
CVE-2019-7314

liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to …

Fix: 0.95+
Fix from $2,300 2019-02-04
Debian Linux HIGH 8.8
CVE-2018-1000878

libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability …

Fix: 3.4.0+
Fix from $1,950 2018-12-20
Debian Linux HIGH 7.8
CVE-2018-19216

Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.

Fix: 2.13.02+
Fix from $1,950 2018-11-12
Debian Linux HIGH 7.8
CVE-2018-9422

In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional p…

Patch available
Fix from $1,950 2018-11-06
Debian Linux HIGH 7.8
CVE-2018-10902

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_…

Patch available
Fix from $1,950 2018-08-21