Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2020-01-16 CVE-2019-5126 Use After Free vulnerability in Foxitsoftware Phantompdf
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit PDF Reader, version 9.7.0.29435.
network
low complexity
foxitsoftware CWE-416
8.8
2020-01-14 CVE-2020-0642 Use After Free vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-416
7.8
2020-01-14 CVE-2020-0634 Use After Free vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-416
7.8
2020-01-14 CVE-2020-7053 Use After Free vulnerability in Linux Kernel
In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c.
local
low complexity
linux CWE-416
7.8
2020-01-11 CVE-2020-6840 Use After Free vulnerability in Mruby 2.1.0
In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.
network
low complexity
mruby CWE-416
critical
9.8
2020-01-11 CVE-2020-6838 Use After Free vulnerability in Mruby 2.1.0
In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.
network
low complexity
mruby CWE-416
critical
9.8
2020-01-10 CVE-2020-6377 Use After Free vulnerability in multiple products
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
8.8
2020-01-10 CVE-2019-13767 Use After Free vulnerability in multiple products
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse CWE-416
8.8
2020-01-08 CVE-2019-17013 Use After Free vulnerability in Mozilla Firefox
Mozilla developers reported memory safety bugs present in Firefox 70.
network
low complexity
mozilla CWE-416
8.8
2020-01-08 CVE-2019-17008 Use After Free vulnerability in multiple products
When using nested workers, a use-after-free could occur during worker destruction.
network
low complexity
mozilla opensuse CWE-416
8.8