Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2017-11-22 CVE-2017-8160 Use After Free vulnerability in Huawei products
The Madapt Driver of some Huawei smart phones with software Earlier than Vicky-AL00AC00B172 versions,Vicky-AL00CC768B122,Vicky-TL00AC01B167,Earlier than Victoria-AL00AC00B172 versions,Victoria-TL00AC00B123,Victoria-TL00AC01B167 has a use after free (UAF) vulnerability.
local
low complexity
huawei CWE-416
7.8
2017-11-22 CVE-2017-8142 Use After Free vulnerability in Huawei Mate 9 Firmware and Mate 9 PRO Firmware
The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and versions earlier than LON-AL00BC00B221 has a use after free (UAF) vulnerability.
local
low complexity
huawei CWE-416
7.8
2017-11-17 CVE-2017-1000211 Use After Free vulnerability in Lynx Project Lynx 2.8.9
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
network
low complexity
lynx-project CWE-416
5.3
2017-11-17 CVE-2017-1000172 Use After Free vulnerability in Creolabs Gravity 1.0
Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution.
network
low complexity
creolabs CWE-416
critical
9.8
2017-11-16 CVE-2017-0861 Use After Free vulnerability in Google Android
Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.
local
low complexity
google CWE-416
7.8
2017-11-16 CVE-2017-11092 Use After Free vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the KGSL driver function kgsl_ioctl_gpu_command, a Use After Free condition can potentially occur.
local
low complexity
google CWE-416
7.8
2017-11-16 CVE-2017-11091 Use After Free vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function mdss_rotator_ioctl in the driver /dev/mdss_rotator, a Use-After-Free condition can potentially occur due to a fence being installed too early.
local
low complexity
google CWE-416
7.8
2017-11-16 CVE-2017-11024 Use After Free vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in the rmnet USB control driver can potentially lead to a Use After Free condition.
local
low complexity
google CWE-416
7.8
2017-11-15 CVE-2017-15115 Use After Free vulnerability in multiple products
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
local
low complexity
linux debian suse canonical CWE-416
7.8
2017-11-15 CVE-2017-15271 Use After Free vulnerability in Psftp Psftpd 10.0.4
A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729.
network
high complexity
psftp CWE-416
5.9