Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2020-07-30 CVE-2020-3701 Use After Free vulnerability in Qualcomm Saipan Firmware, Sm8250 Firmware and Sxr2130 Firmware
Use after free issue while processing error notification from camx driver due to not properly releasing the sequence data in Snapdragon Mobile in Saipan, SM8250, SXR2130
local
low complexity
qualcomm CWE-416
7.8
2020-07-30 CVE-2020-3671 Use After Free vulnerability in Qualcomm products
Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8009, Nicobar, QCM2150, QCS405, Saipan, SDM845, SM8150, SM8250, SXR2130
network
low complexity
qualcomm CWE-416
critical
9.8
2020-07-30 CVE-2019-14037 Use After Free vulnerability in Qualcomm products
Close and bind operations done on a socket can lead to a Use-After-Free condition.
local
low complexity
qualcomm CWE-416
7.8
2020-07-30 CVE-2019-10580 Use After Free vulnerability in Qualcomm products
When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been already freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9607, MSM8909W, Nicobar, QCM2150, QCS405, QCS605, Saipan, SC8180X, SDM429W, SDX55, SM8150, SM8250, SXR2130
local
low complexity
qualcomm CWE-416
7.8
2020-07-29 CVE-2020-15706 Use After Free vulnerability in multiple products
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass.
6.4
2020-07-22 CVE-2020-6518 Use After Free vulnerability in multiple products
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian opensuse fedoraproject CWE-416
8.8
2020-07-22 CVE-2020-6515 Use After Free vulnerability in multiple products
Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian opensuse fedoraproject CWE-416
8.8
2020-07-22 CVE-2020-6509 Use After Free vulnerability in Google Chrome
Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
network
low complexity
google CWE-416
critical
9.6
2020-07-22 CVE-2020-6505 Use After Free vulnerability in Google Chrome
Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
network
low complexity
google CWE-416
critical
9.6
2020-07-21 CVE-2020-15888 Use After Free vulnerability in LUA 5.4.0
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
network
low complexity
lua CWE-416
8.8