Vulnerability index

Browse CVEs

1,822 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 8.8
CVE-2016-5211

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker …

Fix: after 54.0.2840.99
Fix from $1,950 2017-01-19
Chrome HIGH 8.8
CVE-2016-5213

A use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to p…

Fix: after 54.0.2840.99
Fix from $1,950 2017-01-19
Chrome MEDIUM 6.3
CVE-2016-5215

A use after free in webaudio in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacke…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.3
CVE-2016-5216

A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker …

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.3
CVE-2016-5219

A heap use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome HIGH 8.8
CVE-2016-5183

A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android allows a remote attacker…

Fix: after 53.0.2785.143
Fix from $1,950 2016-12-18
Chrome HIGH 8.8
CVE-2016-5184

PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles in CFFL_For…

Fix: after 53.0.2785.143
Fix from $1,950 2016-12-18
Chrome HIGH 8.8
CVE-2016-5185

Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly allowed reentrance of FrameView::updat…

Fix: after 53.0.2785.143
Fix from $1,950 2016-12-18
Chrome MEDIUM 6.3
CVE-2016-5190

Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles during shutdown, whic…

Fix: after 53.0.2785.143
Fix from $1,600 2016-12-18
Chrome HIGH 8.8
CVE-2016-5171

WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, w…

Fix: after 53.0.2785.101
Fix from $1,950 2016-09-25
Chrome HIGH 8.8
CVE-2016-5170

WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter …

Fix: after 53.0.2785.101
Fix from $1,950 2016-09-25
Chrome HIGH 8.8
CVE-2016-5156

extensions/renderer/event_bindings.cc in the event bindings in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux…

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Chrome HIGH 8.8
CVE-2016-5151

PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to …

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Chrome HIGH 8.8
CVE-2016-5150

WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.…

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Chrome CRITICAL 9.8
CVE-2016-5142

The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers,…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
Chrome HIGH 8.8
CVE-2016-5136

Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome before 52.0.2743.82 allows r…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Chrome HIGH 8.8
CVE-2016-5131

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of ser…

Fix: 10.0 / 52.0.2743.82+
Fix from $1,950 2016-07-23
Chrome HIGH 7.5
CVE-2016-5127

Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Google Chrome before 52.0.2743.82, allows remote att…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Chrome HIGH 8.8
CVE-2016-1708

The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider o…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Chrome HIGH 7.5
CVE-2015-1209

Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implemen…

Fix: 40.0.2214.109 / 40.0.2214.111+
Fix from $1,950 2015-02-06
Chrome HIGH 7.5
CVE-2014-3190

Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, a…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Chrome HIGH 7.5
CVE-2014-3191

Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibl…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Chrome HIGH 7.5
CVE-2014-1732

Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and bef…

Fix: 34.0.1847.131 / 34.0.1847.132+
Fix from $1,950 2014-04-26
Chrome HIGH 7.5
CVE-2014-1713

Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome …

Fix: 33.0.1750.152 / 33.0.1750.154+
Fix from $1,950 2014-03-16
Chrome HIGH 7.5
CVE-2013-6641

Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in G…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,950 2014-01-16
Chrome HIGH 7.5
CVE-2013-6644

Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allow attackers to…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,950 2014-01-16
Chrome HIGH 7.5
CVE-2013-6646

Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X an…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,950 2014-01-16
Chrome MEDIUM 6.8
CVE-2013-6645

Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_contents/web_contents_view_aura.cc in Google Chrom…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,600 2014-01-16
Chrome HIGH 7.5
CVE-2013-2856

Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified …

Fix: after 27.0.1453.109
Fix from $1,950 2013-06-05
Chrome HIGH 7.5
CVE-2013-0880

Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers …

Fix: 25.0.1364.97 / 25.0.1364.99+
Fix from $1,950 2013-02-23