Export limit exceeded: 10782 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (10782 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-20542 1 Mediatek 39 Mediatek Chipset, Mt2718, Mt2718 Firmware and 36 more 2026-10-09 6.7 Medium
In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11076799; Issue ID: MSV-8143.
CVE-2026-104113 1 Omnios 1 Omnios 2026-10-09 N/A
A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.
CVE-2026-20537 2 Mediatek, Mediatek, Inc. 23 Mt6878, Mt6878 Firmware, Mt6881 and 20 more 2026-10-09 6.7 Medium
In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185225; Issue ID: MSV-9024.
CVE-2026-95702 1 Google 1 Gvisor 2026-10-09 N/A
Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing MemoryFile from an in-sandbox overlay filesystem. The sentry process remains confined by host-level Linux seccomp and namespace boundaries.
CVE-2026-20531 2 Mediatek, Mediatek, Inc. 13 Mt6899, Mt6899 Firmware, Mt6993 and 10 more 2026-10-09 8.4 High
In apu, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249016; Issue ID: MSV-9169.
CVE-2026-20532 2 Mediatek, Mediatek, Inc. 11 Mt6899, Mt6899 Firmware, Mt6993 and 8 more 2026-10-09 6.2 Medium
In apu, there is a possible application crash due to double free. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249024; Issue ID: MSV-9168.
CVE-2026-108104 1 Xerial 1 Snappy-java 2026-10-09 4.8 Medium
Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that returns pooled buffers twice when replacement allocation fails. Attackers can supply framed data with a large declared chunk length to trigger OutOfMemoryError, causing shared backing arrays that expose or overwrite other streams' decompressed data.
CVE-2026-20536 2 Mediatek, Mediatek, Inc. 27 Mt6878, Mt6878 Firmware, Mt6881 and 24 more 2026-10-09 6.7 Medium
In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11242428; Issue ID: MSV-9038.
CVE-2022-2946 3 Debian, Fedoraproject, Vim 3 Debian Linux, Fedora, Vim 2026-10-09 7.8 High
Use After Free in GitHub repository vim/vim prior to 9.0.0246.
CVE-2026-57559 1 Qualcomm 45 Cologne, Cologne Firmware, Fastconnect 6700 and 42 more 2026-10-09 7.8 High
Memory corruption while processing service requests.
CVE-2026-57555 1 Qualcomm 45 Cologne, Cologne Firmware, Fastconnect 6700 and 42 more 2026-10-09 7.8 High
Memory Corruption when executing system service routines due to improper handling of user input buffers.
CVE-2026-57554 1 Qualcomm 437 Ar8031, Ar8031 Firmware, Ar8035 and 434 more 2026-10-09 7.8 High
Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.
CVE-2026-57537 1 Qualcomm 145 Congo, Congo Firmware, Fastconnect 6200 and 142 more 2026-10-09 7.8 High
Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.
CVE-2026-25291 1 Qualcomm 227 Cq8845s, Cq8845s Firmware, Cq8850ns and 224 more 2026-10-09 7.8 High
Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
CVE-2026-25274 1 Qualcomm 91 Aqt1000, Aqt1000 Firmware, Cologne and 88 more 2026-10-09 6.7 Medium
Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.
CVE-2026-98378 1 Linux 1 Linux Kernel 2026-10-09 N/A
In the Linux kernel, the following vulnerability has been resolved: bpf: Skip unsettled links in link iterator bpf_link_prime() inserts a link into link_idr before anon_inode_getfile() succeeds and before bpf_link_settle() publishes the ID in link->id. bpf_link_by_id() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check. If anon_inode_getfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpf_link_put() accesses freed memory. Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as bpf_link_by_id() does. BUG: KASAN: slab-use-after-free in bpf_link_put Write of size 8 by task exp/384 Call Trace: bpf_link_put kernel/bpf/syscall.c:3372 bpf_link_seq_next kernel/bpf/link_iter.c:33 bpf_seq_read kernel/bpf/bpf_iter.c:158 vfs_read fs/read_write.c:572 ksys_read fs/read_write.c:716 do_syscall_64 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121 Kernel panic - not syncing: KASAN: panic_on_warn set ...
CVE-2026-98381 1 Linux 1 Linux Kernel 2026-10-09 N/A
In the Linux kernel, the following vulnerability has been resolved: veth: manage XDP program pointers during channel resize veth_set_channels() tears down XDP resources for removed RX queues without clearing rq->xdp_prog. If the program is then detached or replaced, those queues keep the old pointer after bpf_prog_put(). A later channel increase can re-enable NAPI and run the freed program. BUG: unable to handle page fault for address: ffffc90000256048 Oops: Oops: 0000 [#1] SMP KASAN NOPTI RIP: veth_xdp_rcv_skb (include/linux/filter.h:779 include/net/xdp.h:696 drivers/net/veth.c:820) Call Trace: veth_xdp_rcv (drivers/net/veth.c:941) veth_poll (drivers/net/veth.c:986) __napi_poll (net/core/dev.c:7787) net_rx_action (net/core/dev.c:7850 net/core/dev.c:8007) handle_softirqs (kernel/softirq.c:645) Kernel panic - not syncing: Fatal exception in interrupt
CVE-2026-98383 1 Linux 1 Linux Kernel 2026-10-09 N/A
In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL An LWT_SEG6LOCAL program can invalidate its cached SRH with bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter may reallocate skb->head, leaving the per-CPU SRH pointer dangling. Post-program SRH validation then writes through that pointer. Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier rejects this unsafe helper combination. Other LWT program types continue to expose the helper through lwt_out_func_proto().
CVE-2026-107886 1 Openprinting 1 Cups 2026-10-09 2.3 Low
OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an existing class member list, add_class() frees pclass->printers without clearing the pointer. If subsequent validation fails, the class retains the dangling pointer; CUPS-Delete-Class subsequently frees the same allocation in cupsdDeletePrinter(). A client authorized to modify and delete classes can cause scheduler-wide denial of service. The default policy requires @SYSTEM privileges.
CVE-2026-5759 1 Falkordb 1 Falkordb 2026-10-09 9.8 Critical
A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time.