Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2017-11-24 CVE-2017-16939 Use After Free vulnerability in multiple products
The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages.
local
low complexity
linux debian CWE-416
7.8
2017-11-22 CVE-2017-8203 Use After Free vulnerability in Huawei Nova 2 Firmware and Nova 2 Plus Firmware
The Bastet Driver of Nova 2 Plus,Nova 2 Huawei smart phones with software of Versions earlier than BAC-AL00C00B173,Versions earlier than PIC-AL00C00B173 has a use after free (UAF) vulnerability.
local
low complexity
huawei CWE-416
7.8
2017-11-22 CVE-2017-8160 Use After Free vulnerability in Huawei products
The Madapt Driver of some Huawei smart phones with software Earlier than Vicky-AL00AC00B172 versions,Vicky-AL00CC768B122,Vicky-TL00AC01B167,Earlier than Victoria-AL00AC00B172 versions,Victoria-TL00AC00B123,Victoria-TL00AC01B167 has a use after free (UAF) vulnerability.
local
low complexity
huawei CWE-416
7.8
2017-11-22 CVE-2017-8142 Use After Free vulnerability in Huawei Mate 9 Firmware and Mate 9 PRO Firmware
The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and versions earlier than LON-AL00BC00B221 has a use after free (UAF) vulnerability.
local
low complexity
huawei CWE-416
7.8
2017-11-17 CVE-2017-1000211 Use After Free vulnerability in Lynx Project Lynx 2.8.9
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
network
low complexity
lynx-project CWE-416
5.3
2017-11-17 CVE-2017-1000172 Use After Free vulnerability in Creolabs Gravity 1.0
Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution.
network
low complexity
creolabs CWE-416
critical
9.8
2017-11-16 CVE-2017-0861 Use After Free vulnerability in Google Android
Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.
local
low complexity
google CWE-416
7.8
2017-11-16 CVE-2017-11092 Use After Free vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the KGSL driver function kgsl_ioctl_gpu_command, a Use After Free condition can potentially occur.
local
low complexity
google CWE-416
7.8
2017-11-16 CVE-2017-11091 Use After Free vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function mdss_rotator_ioctl in the driver /dev/mdss_rotator, a Use-After-Free condition can potentially occur due to a fence being installed too early.
local
low complexity
google CWE-416
7.8
2017-11-16 CVE-2017-11024 Use After Free vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in the rmnet USB control driver can potentially lead to a Use After Free condition.
local
low complexity
google CWE-416
7.8