Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2019-07-15 CVE-2019-6822 Use After Free vulnerability in Schneider-Electric Zelio Soft 2
A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code execution when opening a specially crafted Zelio Soft 2 project file.
local
low complexity
schneider-electric CWE-416
7.8
2019-07-10 CVE-2019-13224 Use After Free vulnerability in multiple products
A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression.
network
low complexity
oniguruma-project php fedoraproject debian canonical CWE-416
critical
9.8
2019-07-08 CVE-2019-2112 Use After Free vulnerability in Google Android 8.0/8.1/9.0
In several functions of alarm.cc, there is possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2019-07-08 CVE-2019-2111 Use After Free vulnerability in Google Android 9.0
In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free.
network
low complexity
google CWE-416
critical
9.8
2019-07-04 CVE-2019-13289 Use After Free vulnerability in Glyphandcog Xpdfreader 4.01.01
In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc.
local
low complexity
glyphandcog CWE-416
7.8
2019-07-04 CVE-2019-13233 Use After Free vulnerability in Linux Kernel
In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.
local
high complexity
linux CWE-416
7.0
2019-06-29 CVE-2019-13045 Use After Free vulnerability in Irssi
Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.
network
high complexity
irssi CWE-416
8.1
2019-06-27 CVE-2019-5828 Use After Free vulnerability in multiple products
Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-416
8.8
2019-06-27 CVE-2019-5813 Use After Free vulnerability in multiple products
Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-416
8.8
2019-06-27 CVE-2019-5809 Use After Free vulnerability in multiple products
Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-416
8.8