Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2021-30473

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
Attacker Value
Unknown

CVE-2021-24028

Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00.
Attacker Value
Unknown

CVE-2021-21401

Disclosure Date: March 23, 2021 (last updated February 22, 2025)
Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, decoding a specifically formed message can cause invalid `free()` or `realloc()` calls if the message type contains an `oneof` field, and the `oneof` directly contains both a pointer field and a non-pointer field. If the message data first contains the non-pointer field and then the pointer field, the data of the non-pointer field is incorrectly treated as if it was a pointer value. Such message data rarely occurs in normal messages, but it is a concern when untrusted data is parsed. This has been fixed in versions 0.3.9.8 and 0.4.5. See referenced GitHub Security Advisory for more information including workarounds.
Attacker Value
Unknown

CVE-2020-36224

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
Attacker Value
Unknown

CVE-2020-0444

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150693166References: Upstream kernel
Attacker Value
Unknown

CVE-2020-28941

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.
Attacker Value
Unknown

CVE-2020-5139

Disclosure Date: October 12, 2020 (last updated February 22, 2025)
A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Invalid pointer and leads to a firewall crash. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0.
Attacker Value
Unknown

CVE-2020-24371

Disclosure Date: August 17, 2020 (last updated February 21, 2025)
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.
Attacker Value
Unknown

CVE-2020-8715

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
Invalid pointer for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable denial of service via local access.
Attacker Value
Unknown

CVE-2019-18619

Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.