VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,277)

page 102 of 414
  • CVE-2022-1144HigJul 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.

  • CVE-2022-1141HigJul 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.

  • CVE-2022-1136HigJul 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific set of user gestures.

  • CVE-2022-1135HigJul 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Shopping Cart in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via standard feature user interaction.

  • CVE-2022-1133HigJul 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebRTC Perf in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-1131HigJul 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Cast UI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-1127HigJul 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in QR Code Generator in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

  • CVE-2022-1125HigJul 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Portals in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

  • CVE-2022-0980HigJul 22, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions.

  • CVE-2022-0979HigJul 22, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0978HigJul 22, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0975HigJul 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0974HigJul 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Splitscreen in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0972HigJul 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0971HigJul 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-21745HigJun 6, 2022
    risk 0.57cvss 8.8epss 0.00

    In WIFI Firmware, there is a possible memory corruption due to a use after free. This could lead to remote escalation of privilege, when devices are connecting to the attacker-controllable Wi-Fi hotspot, with no additional execution privileges needed. User interaction is not…

  • CVE-2022-27046HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.01

    libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.

  • CVE-2021-41715HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.01

    libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.

  • CVE-2022-0808HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in a series of user interaction to potentially exploit heap corruption via user interactions.

  • CVE-2022-0805HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.