Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Hardened Images HIGH 7.3
CVE-2026-71226

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allo…

Fix: 1.5.1+
Fix from $1,950 2026-08-05
Hardened Images HIGH 7.5
CVE-2026-59850

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data …

No fix yet
Fix from $1,950 2026-07-21
Hardened Images MEDIUM 5.3
CVE-2026-13595

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers …

Fix: 2.42.2+
Fix from $1,600 2026-06-29
Directory Server MEDIUM 5.0
CVE-2026-11791

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information…

Mitigation only
Fix from $1,600 2026-06-18
Enterprise Linux HIGH 7.8
CVE-2026-50260

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those …

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Enterprise Linux HIGH 7.8
CVE-2026-50261

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a …

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Enterprise Linux MEDIUM 5.5
CVE-2026-50263

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing …

Fix: 21.1.23 / 24.1.12+
Fix from $1,600 2026-06-05
Enterprise Linux HIGH 7.8
CVE-2026-50257

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger…

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Enterprise Linux HIGH 7.5
CVE-2026-4271

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme…

No fix yet
Fix from $1,950 2026-03-17
Enterprise Linux HIGH 7.8
CVE-2025-26600

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while th…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26601

A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, chang…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux HIGH 7.8
CVE-2025-26594

A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root…

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Codeready Linux Builder For Eus MEDIUM 6.7
CVE-2024-0193

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is r…

Patch available
Fix from $1,600 2024-01-02
Enterprise Linux HIGH 7.0
CVE-2023-5574

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setu…

Patch available
Fix from $1,950 2023-10-25
Codeready Linux Builder Eus MEDIUM 5.9
CVE-2023-4806

A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an …

Mitigation only
Fix from $1,600 2023-09-18
Enterprise Linux HIGH 8.2
CVE-2023-2680

This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 …

Mitigation only
Fix from $1,950 2023-09-13
Enterprise Linux MEDIUM 5.9
CVE-2023-4813

A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application…

Patch available
Fix from $1,600 2023-09-12
Enterprise Linux MEDIUM 6.5
CVE-2023-3019

A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged gues…

Fix: 8.2.0+
Fix from $1,600 2023-07-24
Enterprise Linux HIGH 8.8
CVE-2023-2203

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers …

Mitigation only
Fix from $1,950 2023-05-17
Enterprise Linux Server HIGH 7.5
CVE-2022-2738

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t…

Mitigation only
Fix from $1,950 2022-09-01
Enterprise Linux HIGH 7.5
CVE-2022-0934

A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dns…

Fix: 2.87+
Fix from $1,950 2022-08-29
Libvirt MEDIUM 6.5
CVE-2021-3975

A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads with…

Fix: 7.1.0+
Fix from $1,600 2022-08-23
Enterprise Linux HIGH 8.2
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO regi…

Fix: 7.0.0+
Fix from $1,950 2022-05-02
Enterprise Linux MEDIUM 6.4
CVE-2021-3700

A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c…

Fix: 0.11.0+
Fix from $1,600 2022-02-24
Enterprise Linux MEDIUM 6.7
CVE-2021-3543

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descri…

Fix: 5.10.0+
Fix from $1,600 2021-06-01
Enterprise Linux CRITICAL 9.8
CVE-2020-36329

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this…

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.8
CVE-2021-20231

A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.

Fix: 3.7.1+
Fix from $2,300 2021-03-12
Enterprise Linux CRITICAL 9.8
CVE-2021-20232

A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potentia…

Fix: 3.7.1+
Fix from $2,300 2021-03-12
Enterprise Linux HIGH 7.8
CVE-2021-3403

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) …

No fix yet
Fix from $1,950 2021-03-04
Enterprise Linux HIGH 8.2
CVE-2020-25632

A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking …

Fix: 2.06+
Fix from $1,950 2021-03-03