Vulnerability index

Browse CVEs

171 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Debian Linux MEDIUM 6.5
CVE-2017-14528

The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply …

No fix yet
Fix from $1,600 2017-09-18
Debian Linux HIGH 7.5
CVE-2017-13711

Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEM…

Fix: after 2.10.1
Fix from $1,950 2017-09-01
Debian Linux MEDIUM 6.5
CVE-2017-13737

There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.

Patch available
Fix from $1,600 2017-08-29
Debian Linux MEDIUM 6.5
CVE-2017-12877

Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of servi…

Fix: 6.9.9-6 / 7.0.6-6+
Fix from $1,600 2017-08-28
Debian Linux HIGH 8.8
CVE-2017-12936EPSS 25%

The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.

Patch available
Fix from $1,950 2017-08-18
Debian Linux HIGH 7.8
CVE-2017-9612

The Ins_IP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (use-after-free and …

No fix yet
Fix from $1,950 2017-07-26
Debian Linux HIGH 7.8
CVE-2017-9527

The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and applicati…

Fix: after 1.2.0
Fix from $1,950 2017-06-11
Debian Linux CRITICAL 9.8
CVE-2017-2518EPSS 5%

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $2,300 2017-05-22
Debian Linux MEDIUM 5.5
CVE-2017-8846

The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and applicati…

Patch available
Fix from $1,600 2017-05-08
Debian Linux HIGH 7.5
CVE-2017-5194

Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to cause a denial of service (crash) via an invalid nick message.

Fix: 0.8.21+
Fix from $1,950 2017-03-03
Debian Linux MEDIUM 5.5
CVE-2016-9401

popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.

Fix: 4.4+
Fix from $1,600 2017-01-23
Debian Linux MEDIUM 5.5
CVE-2016-7906

magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.

Patch available
Fix from $1,600 2017-01-18
Debian Linux CRITICAL 9.8
CVE-2015-8871

Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact v…

Fix: after 2.1.0
Fix from $2,300 2016-09-21
Debian Linux MEDIUM 5.9
CVE-2016-7180

epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant…

Patch available
Fix from $1,600 2016-09-09
Debian Linux CRITICAL 9.8
CVE-2015-8949

Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call …

Patch available
Fix from $2,300 2016-08-19
Debian Linux CRITICAL 9.8
CVE-2014-9906EPSS 6%

Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary c…

Fix: after 4.028
Fix from $2,300 2016-08-19
Debian Linux MEDIUM 5.0
CVE-2013-4560EPSS 5%

Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspec…

Fix: 1.4.33+
Fix from $1,600 2013-11-20
Debian Linux HIGH 7.5
CVE-2013-2873

Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 28.0.1500.70
Fix from $1,950 2013-07-10
Debian Linux HIGH 7.5
CVE-2013-2860

Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified …

Fix: after 27.0.1453.109
Fix from $1,950 2013-06-05
Debian Linux HIGH 7.5
CVE-2013-2857

Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified …

Fix: after 27.0.1453.109
Fix from $1,950 2013-06-05
Debian Linux HIGH 7.5
CVE-2013-2858

Use-after-free vulnerability in the HTML5 Audio implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of ser…

Fix: after 27.0.1453.109
Fix from $1,950 2013-06-05