Skip to main content

CWE archive

CWE-667 CVEs

Programmatic archive

718 CVEs tagged with CWE-6673 Critical, 111 High, 589 Medium, 15 Low, 0 Unrated.

CVE-2020-0423

Published Oct 14, 2020

In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0420

Published Oct 14, 2020

In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escalation of privilege with no addi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15674

Published Oct 1, 2020

Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15668

Published Oct 1, 2020

A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android <…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0357

Published Sep 17, 2020

In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the graphics server with no additional execution…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0303

Published Sep 17, 2020

In the Media extractor, there is a possible use after free due to improper locking. This could lead to remote code execution in the media extractor with no additional execution pr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0433

Published Sep 17, 2020

In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional exec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0243

Published Aug 11, 2020

In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0242

Published Aug 11, 2020

In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15529

Published Jul 5, 2020

An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13246

Published May 20, 2020

An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10573

Published Mar 14, 2020

An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17343

Published Oct 8, 2019

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9268

Published Sep 27, 2019

In libstagefright, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution pr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9447

Published Sep 6, 2019

In the Android kernel in the FingerTipS touchscreen driver there is a possible use-after-free due to improper locking. This could lead to a local escalation of privilege with Syst…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9275

Published Sep 6, 2019

In the Android kernel in the mnh driver there is a use after free due to improper locking. This could lead to escalation of privilege with System execution privileges needed. User…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9273

Published Sep 6, 2019

In the Android kernel in the synaptics_dsx_htc touchscreen driver there is a possible use after free due to improper locking. This could lead to local escalation of privilege with…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-2174

Published Sep 5, 2019

In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper locking. This could lead to l…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 651-675 of 718 CVEsPage 27 of 29