Vulnerability index

Browse CVEs

1,622 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Linux Kernel MEDIUM 6.8
CVE-2019-19531

In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/yurex.c driver, …

Fix: 5.2.9+
Fix from $1,600 2019-12-03
Linux Kernel MEDIUM 6.3
CVE-2019-19529

In the Linux kernel before 5.3.11, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c d…

Fix: 5.3.11+
Fix from $1,600 2019-12-03
Linux Kernel MEDIUM 6.1
CVE-2019-19528

In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driv…

Fix: 5.3.7+
Fix from $1,600 2019-12-03
Linux Kernel MEDIUM 6.8
CVE-2019-19527

In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driv…

Fix: 3.16.79 / 4.4.190+
Fix from $1,600 2019-12-03
Linux Kernel HIGH 7.8
CVE-2019-19377

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btr…

Fix: 4.19.156 / 5.4.33+
Fix from $1,950 2019-11-29
Linux Kernel MEDIUM 6.5
CVE-2019-19319

In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of a…

Patch available
Fix from $1,600 2019-11-27
Linux Kernel CRITICAL 9.8
CVE-2019-18814

An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/…

Fix: after 5.3.9
Fix from $2,300 2019-11-07
Linux Kernel HIGH 7.0
CVE-2019-18683

An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux d…

Fix: 4.4.204 / 4.9.204+
Fix from $1,950 2019-11-04
Linux Kernel MEDIUM 5.5
CVE-2018-21008

An issue was discovered in the Linux kernel before 4.16.7. A use-after-free can be caused by the function rsi_mac80211_detach in the file drivers/net…

Fix: 4.16.7+
Fix from $1,600 2019-09-04
Linux Kernel HIGH 7.0
CVE-2019-15917

An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() fails in hci_uart_set_proto() …

Fix: 3.13 / 4.9.202+
Fix from $1,950 2019-09-04
Linux Kernel HIGH 7.8
CVE-2019-15239

In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier …

Patch available
Fix from $1,950 2019-08-20
Linux Kernel MEDIUM 6.4
CVE-2019-15214

An issue was discovered in the Linux kernel before 5.0.10. There is a use-after-free in the sound subsystem because card disconnection causes certain…

Fix: 5.0.10+
Fix from $1,600 2019-08-19
Linux Kernel HIGH 7.8
CVE-2018-20976

An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure.

Fix: 4.18+
Fix from $1,950 2019-08-19
Linux Kernel HIGH 7.8
CVE-2016-10905

An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rinde…

Fix: 3.16.74 / 4.4.191+
Fix from $1,950 2019-08-19
Linux Kernel HIGH 7.0
CVE-2016-10906

An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caused by a race condition betwee…

Fix: 4.5+
Fix from $1,950 2019-08-19
Linux Kernel HIGH 7.8
CVE-2018-20856

An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain erro…

Fix: 4.18.7+
Fix from $1,950 2019-07-26
Linux Kernel HIGH 7.0
CVE-2019-13233

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition betwee…

Fix: 5.1.9+
Fix from $1,950 2019-07-04
Linux Kernel HIGH 7.8
CVE-2019-3896

A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a priv…

Fix: after 2.6.39.4
Fix from $1,950 2019-06-19
Linux Kernel MEDIUM 5.5
CVE-2019-12819

An issue was discovered in the Linux kernel before 5.0. The function __mdiobus_register() in drivers/net/phy/mdio_bus.c calls put_device(), which wil…

Fix: 5.0+
Fix from $1,600 2019-06-14
Linux Kernel HIGH 8.1
CVE-2019-11815

An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free…

Fix: 4.4.179 / 4.9.169+
Fix from $1,950 2019-05-08
Linux Kernel HIGH 8.1
CVE-2018-20836EPSS 5%

An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/…

Fix: 3.16.72 / 3.18.140+
Fix from $1,950 2019-05-07
Linux Kernel HIGH 7.5
CVE-2019-11810EPSS 6%

An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_allo…

Fix: 3.16.69 / 3.18.139+
Fix from $1,950 2019-05-07
Linux Kernel HIGH 7.0
CVE-2019-11811

An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si mod…

Fix: 4.19.31 / 5.0.4+
Fix from $1,950 2019-05-07
Linux Kernel HIGH 7.8
CVE-2019-11487

The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists…

Fix: 4.4.216 / 4.9.181+
Fix from $1,950 2019-04-23
Linux Kernel HIGH 7.8
CVE-2019-8956

In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP…

Fix: 4.19.21 / 4.20.8+
Fix from $1,950 2019-04-01
Linux Kernel CRITICAL 9.8
CVE-2019-10125EPSS 5%

An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event i…

Fix: 4.19.38 / 5.0.5+
Fix from $2,300 2019-03-27
Linux Kernel HIGH 7.8
CVE-2019-7221

The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.

Fix: after 4.20.5
Fix from $1,950 2019-03-21
Linux Kernel HIGH 7.5
CVE-2019-9003

In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simul…

Fix: 4.19.18 / 4.20.5+
Fix from $1,950 2019-02-22
Linux Kernel HIGH 7.8
CVE-2019-8912

In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to …

Fix: 4.14.103 / 4.19.25+
Fix from $1,950 2019-02-18
Linux Kernel HIGH 8.1
CVE-2019-6974EPSS 17%

In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading …

Fix: 3.16.64 / 3.18.136+
Fix from $1,950 2019-02-15