VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,274)

page 108 of 414
  • CVE-2021-21870HigAug 5, 2021
    risk 0.57cvss 8.8epss 0.02

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.4.37651. A specially crafted PDF document can trigger the reuse of previously free memory, which can lead to arbitrary code execution. An attacker needs to trick the…

  • CVE-2021-29972HigAug 5, 2021
    risk 0.57cvss 8.8epss 0.01

    A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well. This vulnerability affects Firefox < 90.

  • CVE-2021-29970HigAug 5, 2021
    risk 0.57cvss 8.8epss 0.01

    A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when accessibility was enabled.*. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.

  • CVE-2021-30586HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in dialog box handling in Windows in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30585HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in sensor handling in Google Chrome on Windows prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30581HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30579HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.02

    Use after free in UI framework in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30576HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30574HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.02

    Use after free in protocol handling in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30572HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.02

    Use after free in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30569HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30567HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to open DevTools to potentially exploit heap corruption via specific user gesture.

  • CVE-2021-30562HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30541HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.02

    Use after free in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21806HigJul 8, 2021
    risk 0.57cvss 8.8epss 0.03

    An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in remote code execution. The victim needs to visit a malicious web site to trigger the vulnerability.

  • CVE-2021-21779HigJul 8, 2021
    risk 0.57cvss 8.8epss 0.03

    A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web…

  • CVE-2021-30556HigJul 2, 2021
    risk 0.57cvss 8.8epss 0.02

    Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30555HigJul 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and user gesture.

  • CVE-2021-30553HigJun 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30552HigJun 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.