Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2019-06-11 CVE-2019-0196 Use After Free vulnerability in multiple products
A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38.
network
low complexity
apache canonical debian CWE-416
5.3
2019-06-10 CVE-2018-20356 Use After Free vulnerability in Cesanta Mongoose
An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
network
low complexity
cesanta CWE-416
critical
9.8
2019-06-10 CVE-2018-20355 Use After Free vulnerability in Cesanta Mongoose
An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
network
low complexity
cesanta CWE-416
critical
9.8
2019-06-10 CVE-2018-20354 Use After Free vulnerability in Cesanta Mongoose
An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
network
low complexity
cesanta CWE-416
critical
9.8
2019-06-10 CVE-2018-20353 Use After Free vulnerability in Cesanta Mongoose
An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
network
low complexity
cesanta CWE-416
critical
9.8
2019-06-10 CVE-2018-20352 Use After Free vulnerability in Cesanta Mongoose Embedded web Server Library
Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
network
low complexity
cesanta CWE-416
8.8
2019-06-07 CVE-2019-2095 Use After Free vulnerability in Google Android 9.0
In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race condition.
local
high complexity
google CWE-416
7.0
2019-06-07 CVE-2018-19452 Use After Free vulnerability in Foxitsoftware Foxit PDF SDK Activex 5.4.0.1031/5.5.0
A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031.
local
low complexity
foxitsoftware CWE-416
7.8
2019-06-06 CVE-2019-5525 Use After Free vulnerability in VMWare Workstation
VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend.
local
low complexity
vmware CWE-416
8.8
2019-06-06 CVE-2019-5214 Use After Free vulnerability in Huawei Mate 10 Firmware
There is a use after free vulnerability on certain driver component in Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0.0.167(C00E85R2P20T8).
local
low complexity
huawei CWE-416
5.5