Export limit exceeded: 403070 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (9722 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76875 | 1 Pypy | 1 Pypy | 2026-10-02 | 5.3 Medium |
| PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption. | ||||
| CVE-2026-74222 | 2 Denx, U-boot | 2 U-boot, U-boot | 2026-10-02 | 8.2 High |
| U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead of ERR_ABRT, causing the TCP input path to access released memory and crash the bootloader. | ||||
| CVE-2021-26411 | 1 Microsoft | 17 Edge, Internet Explorer, Windows 10 1507 and 14 more | 2026-10-01 | 8.8 High |
| Internet Explorer Memory Corruption Vulnerability | ||||
| CVE-2018-15982 | 6 Adobe, Apple, Google and 3 more | 12 Flash Player, Flash Player Installer, Mac Os X and 9 more | 2026-10-01 | 7.8 High |
| Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | ||||
| CVE-2026-84895 | 1 Facebook | 1 Proxygen | 2026-10-01 | 7.3 High |
| In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it. | ||||
| CVE-2026-58185 | 1 Apache | 1 Traffic Server | 2026-10-01 | 5.9 Medium |
| The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. | ||||
| CVE-2026-58164 | 1 Apache | 1 Traffic Server | 2026-10-01 | 7.5 High |
| Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. | ||||
| CVE-2026-101276 | 1 Es | 1 Iperf3 | 2026-10-01 | N/A |
| iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22. | ||||
| CVE-2026-57842 | 1 Netbsd | 1 Netbsd | 2026-10-01 | 7 High |
| NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing the kernel to access a freed iovec buffer and subsequently free the same allocation a second time. | ||||
| CVE-2026-69576 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-10-01 | 7.8 High |
| Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69546 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-10-01 | 8.1 High |
| Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69524 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-10-01 | 8.1 High |
| Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2023-1989 | 4 Debian, Linux, Netapp and 1 more | 11 Debian Linux, Linux Kernel, H300s and 8 more | 2026-10-01 | 7 High |
| A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices. | ||||
| CVE-2026-47500 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-10-01 | 7.8 High |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where improper cleanup of reference counts during error paths could lead to a use-after-free condition. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47516 | 1 Nvidia | 6 Geforce, Guest Driver, Nvs and 3 more | 2026-10-01 | 7.8 High |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-84894 | 1 Meta Platforms Inc | 1 Moxygen | 2026-10-01 | 7.5 High |
| In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write. | ||||
| CVE-2026-91096 | 1 Facebook | 1 Proxygen | 2026-10-01 | 7.5 High |
| In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been freed. | ||||
| CVE-2026-91095 | 1 Facebook | 1 Proxygen | 2026-10-01 | 5.3 Medium |
| In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory. | ||||
| CVE-2026-100761 | 1 Mozilla | 1 Firefox | 2026-10-01 | 8.8 High |
| Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100762 | 1 Mozilla | 1 Firefox | 2026-10-01 | 9.6 Critical |
| Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||