Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2019-07-23 CVE-2019-11691 Use After Free vulnerability in Mozilla Thunderbird
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed.
network
low complexity
mozilla CWE-416
critical
9.8
2019-07-23 CVE-2019-1010170 Use After Free vulnerability in Jsish 2.4.772.0477
Jsish 2.4.77 2.0477 is affected by: Use After Free.
network
low complexity
jsish CWE-416
7.5
2019-07-22 CVE-2019-2264 Use After Free vulnerability in Qualcomm products
Null pointer dereference occurs for channel context while opening glink channel in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9607, MDM9640, MSM8909W, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SDM439, SDM630, SDM660, SDX24
local
low complexity
qualcomm CWE-416
7.8
2019-07-22 CVE-2019-2260 Use After Free vulnerability in Qualcomm products
A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM439, SDM630, SDM660, SDX20, SDX24, Snapdragon_High_Med_2016, SXR1130
local
high complexity
qualcomm CWE-416
7.0
2019-07-15 CVE-2019-6822 Use After Free vulnerability in Schneider-Electric Zelio Soft 2
A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code execution when opening a specially crafted Zelio Soft 2 project file.
local
low complexity
schneider-electric CWE-416
7.8
2019-07-10 CVE-2019-13224 Use After Free vulnerability in multiple products
A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression.
network
low complexity
oniguruma-project php fedoraproject debian canonical CWE-416
critical
9.8
2019-07-08 CVE-2019-2112 Use After Free vulnerability in Google Android 8.0/8.1/9.0
In several functions of alarm.cc, there is possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2019-07-08 CVE-2019-2111 Use After Free vulnerability in Google Android 9.0
In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free.
network
low complexity
google CWE-416
critical
9.8
2019-07-04 CVE-2019-13289 Use After Free vulnerability in Glyphandcog Xpdfreader 4.01.01
In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc.
local
low complexity
glyphandcog CWE-416
7.8
2019-07-04 CVE-2019-13233 Use After Free vulnerability in Linux Kernel
In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.
local
high complexity
linux CWE-416
7.0