Vulnerability index

Browse CVEs

1,820 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 8.6
CVE-2021-21207

Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to poten…

Fix: 90.0.4430.72+
Fix from $1,950 2021-04-26
Android HIGH 7.8
CVE-2021-0442

In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a use after free. This could lead…

Patch available
Fix from $1,950 2021-04-13
Android HIGH 7.8
CVE-2021-0429

In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no add…

Patch available
Fix from $1,950 2021-04-13
Chrome HIGH 8.8
CVE-2021-21194

Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 89.0.4389.114+
Fix from $1,950 2021-04-09
Chrome HIGH 8.8
CVE-2021-21195

Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 89.0.4389.114+
Fix from $1,950 2021-04-09
Chrome HIGH 8.8
CVE-2021-21199

Use after free in Aura in Google Chrome on Linux prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potenti…

Fix: 89.0.4389.114+
Fix from $1,950 2021-04-09
Chrome HIGH 8.8
CVE-2021-21193 KEVEPSS 10%

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 89.0.4389.90+
Fix from $1,950 2021-03-16
Chrome HIGH 8.8
CVE-2021-21191

Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 89.0.4389.90+
Fix from $1,950 2021-03-16
Android HIGH 7.8
CVE-2021-0395

In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0399

In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,950 2021-03-10
Chrome HIGH 8.8
CVE-2021-21179

Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption …

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21180

Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21188

Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21167

Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21159

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21162

Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome CRITICAL 9.6
CVE-2021-21150

Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to …

Fix: 88.0.4324.182+
Fix from $2,300 2021-02-22
Chrome CRITICAL 9.6
CVE-2021-21151

Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HT…

Fix: 88.0.4324.182+
Fix from $2,300 2021-02-22
Android HIGH 7.8
CVE-2021-0332

In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privileg…

Patch available
Fix from $1,950 2021-02-10
Android MEDIUM 6.5
CVE-2021-0335

In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to remote information disclosure wi…

Patch available
Fix from $1,600 2021-02-10
Android HIGH 7.8
CVE-2021-0330

In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of…

Patch available
Fix from $1,950 2021-02-10
Chrome CRITICAL 9.6
CVE-2021-21142

Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a cra…

Fix: 88.0.4324.146+
Fix from $2,300 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21146

Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 88.0.4324.146+
Fix from $2,300 2021-02-09
Chrome HIGH 8.8
CVE-2021-21145

Use after free in Fonts in Google Chrome prior to 88.0.4324.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 88.0.4324.146+
Fix from $1,950 2021-02-09
Chrome HIGH 8.6
CVE-2021-21138

Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sandbox escape via a crafted file.

Fix: 88.0.4324.96+
Fix from $1,950 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21121EPSS 6%

Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a cra…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $2,300 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21124EPSS 8%

Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a s…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $2,300 2021-02-09
Chrome HIGH 8.8
CVE-2021-21119EPSS 7%

Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially expl…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,950 2021-02-09
Chrome HIGH 8.8
CVE-2021-21120EPSS 7%

Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,950 2021-02-09
Chrome HIGH 8.8
CVE-2021-21122EPSS 7%

Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,950 2021-02-09