VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,274)

page 109 of 414
  • CVE-2021-30550HigJun 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30549HigJun 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30548HigJun 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30546HigJun 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Autofill in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30545HigJun 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30544HigJun 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-24037CriJun 15, 2021
    risk 0.57cvss 9.8epss 0.02

    A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits…

  • CVE-2021-0475HigJun 11, 2021
    risk 0.57cvss 8.8epss 0.01

    In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-30543HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30542HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30529HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30528HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had compromised the renderer process of a user who had saved a credit card in their Google account to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30527HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30525HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30524HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30523HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

  • CVE-2021-30522HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30520HigJun 4, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30519HigJun 4, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30515HigJun 4, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.