Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2017-09-18 CVE-2017-14528 Use After Free vulnerability in multiple products
The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply that data validation has occurred, which allows remote attackers to cause a denial of service (use-after-free after an invalid call to TIFFSetField, and application crash) via a crafted file.
network
low complexity
imagemagick debian CWE-416
6.5
2017-09-07 CVE-2017-12133 Use After Free vulnerability in GNU Glibc
Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.
network
high complexity
gnu CWE-416
5.9
2017-09-05 CVE-2017-2821 Use After Free vulnerability in Lexmark Perceptive Document Filters 11.3.0.2400/11.4.0.2452
An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.2400 and 11.4.0.2452.
network
low complexity
lexmark CWE-416
8.8
2017-09-05 CVE-2017-2808 Use After Free vulnerability in Ledger-Cli Ledger 3.1.1
An exploitable use-after-free vulnerability exists in the account parsing component of the Ledger-CLI 3.1.1.
local
low complexity
ledger-cli CWE-416
7.8
2017-09-01 CVE-2017-14103 Use After Free vulnerability in Graphicsmagick 1.3.26
The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote attackers to conduct use-after-free attacks via a crafted file, related to a ReadMNGImage out-of-order CloseBlob call.
network
low complexity
graphicsmagick CWE-416
8.8
2017-09-01 CVE-2017-13711 Use After Free vulnerability in multiple products
Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.
network
low complexity
qemu debian CWE-416
7.5
2017-08-29 CVE-2017-13741 Use After Free vulnerability in Liblouis 3.2.0
There is a use-after-free in the function compileBrailleIndicator() in compileTranslationTable.c in Liblouis 3.2.0 that will lead to a remote denial of service attack.
network
low complexity
liblouis CWE-416
6.5
2017-08-29 CVE-2017-13737 Use After Free vulnerability in multiple products
There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.
network
low complexity
graphicsmagick debian CWE-416
6.5
2017-08-28 CVE-2017-12877 Use After Free vulnerability in multiple products
Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.
network
low complexity
imagemagick debian canonical CWE-416
6.5
2017-08-19 CVE-2017-10661 Use After Free vulnerability in multiple products
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
local
high complexity
linux redhat debian CWE-416
7.0