Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2017-03-14 CVE-2017-6874 Use After Free vulnerability in Linux Kernel
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.
local
high complexity
linux CWE-416
7.0
2017-03-07 CVE-2016-10200 Use After Free vulnerability in multiple products
Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
local
high complexity
linux google CWE-416
7.0
2017-03-03 CVE-2017-5194 Use After Free vulnerability in multiple products
Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to cause a denial of service (crash) via an invalid nick message.
network
low complexity
irssi debian CWE-416
7.5
2017-03-01 CVE-2017-6346 Use After Free vulnerability in Linux Kernel
Race condition in net/packet/af_packet.c in the Linux kernel before 4.9.13 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that makes PACKET_FANOUT setsockopt system calls.
local
high complexity
linux CWE-416
7.0
2017-03-01 CVE-2017-5666 Use After Free vulnerability in Mp3Splt Project Mp3Splt 2.6.2
The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a crafted file.
local
low complexity
mp3splt-project CWE-416
5.5
2017-02-24 CVE-2016-4488 Use After Free vulnerability in GNU Libiberty
Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "ktypevec."
local
low complexity
gnu CWE-416
5.5
2017-02-24 CVE-2016-4487 Use After Free vulnerability in GNU Libiberty
Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec."
local
low complexity
gnu CWE-416
5.5
2017-02-24 CVE-2017-6196 Use After Free vulnerability in Artifex Afpl Ghostscript
Multiple use-after-free vulnerabilities in the gx_image_enum_begin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739d9b1a283 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document.
local
low complexity
artifex CWE-416
7.8
2017-02-23 CVE-2016-10109 Use After Free vulnerability in multiple products
Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.
network
low complexity
muscle canonical CWE-416
7.5
2017-02-20 CVE-2017-2360 Use After Free vulnerability in multiple products
An issue was discovered in certain Apple products.
local
low complexity
apple webkitgtk CWE-416
7.8