Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2020-12-03 CVE-2020-13531 Use After Free vulnerability in Pixar Openusd 20.08
A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files.
network
low complexity
pixar CWE-416
8.8
2020-11-28 CVE-2019-20934 Use After Free vulnerability in Linux Kernel
An issue was discovered in the Linux kernel before 5.2.6.
local
high complexity
linux CWE-416
5.3
2020-11-26 CVE-2020-27207 Use After Free vulnerability in Zetetic Sqlcipher 4.0
Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite3.c.
network
low complexity
zetetic CWE-416
7.5
2020-11-23 CVE-2020-15436 Use After Free vulnerability in multiple products
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
local
low complexity
linux broadcom netapp CWE-416
6.7
2020-11-23 CVE-2019-14586 Use After Free vulnerability in multiple products
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.
low complexity
tianocore debian CWE-416
8.0
2020-11-23 CVE-2019-2393 Use After Free vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations.
network
low complexity
mongodb CWE-416
6.5
2020-11-20 CVE-2020-4004 Use After Free vulnerability in VMWare products
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller.
local
low complexity
vmware CWE-416
8.2
2020-11-19 CVE-2020-28951 Use After Free vulnerability in Openwrt
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names.
network
low complexity
openwrt CWE-416
critical
9.8
2020-11-12 CVE-2020-8750 Use After Free vulnerability in Intel Trusted Execution Engine 3.0/3.1.75/4.0.25
Use after free in Kernel Mode Driver for Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-416
7.8
2020-11-12 CVE-2020-12303 Use After Free vulnerability in Intel products
Use after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.
local
low complexity
intel CWE-416
7.8