Vulnerabilities > Use After Free

DATE CVE VULNERABILITY TITLE RISK
2017-07-25 CVE-2015-5221 Use After Free vulnerability in multiple products
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
5.5
2017-07-18 CVE-2017-11403 Use After Free vulnerability in Graphicsmagick 1.3.26
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.
network
low complexity
graphicsmagick CWE-416
8.8
2017-07-17 CVE-2017-11337 Use After Free vulnerability in Exiv2 0.26
There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26.
network
low complexity
exiv2 CWE-416
6.5
2017-07-13 CVE-2017-9789 Use After Free vulnerability in Apache Http Server 2.4.26
When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
network
low complexity
apache CWE-416
7.5
2017-07-11 CVE-2017-11176 Use After Free vulnerability in multiple products
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic.
local
low complexity
linux debian CWE-416
7.8
2017-07-08 CVE-2017-11109 Use After Free vulnerability in VIM 8.0
Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file.
local
low complexity
vim CWE-416
7.8
2017-07-07 CVE-2017-10966 Use After Free vulnerability in Irssi
An issue was discovered in Irssi before 1.0.4.
network
low complexity
irssi CWE-416
critical
9.8
2017-07-01 CVE-2017-10788 Use After Free vulnerability in Dbd-Mysql Project Dbd-Mysql
The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server.
network
low complexity
dbd-mysql-project CWE-416
critical
9.8
2017-06-29 CVE-2017-10686 Use After Free vulnerability in multiple products
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm.
local
low complexity
nasm canonical CWE-416
7.8
2017-06-29 CVE-2017-10672 Use After Free vulnerability in multiple products
Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
network
low complexity
xml-libxml-project debian CWE-416
critical
9.8