VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,274)

page 129 of 414
  • CVE-2025-69627HigApr 13, 2026
    risk 0.55cvss 8.4epss 0.00

    Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely, after which the freed pointer is still passed into UI…

  • CVE-2026-24930HigFeb 6, 2026
    risk 0.55cvss 8.4epss 0.00

    UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-20953HigJan 13, 2026
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-20952HigJan 13, 2026
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-62557HigDec 9, 2025
    risk 0.55cvss 8.4epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-58303HigNov 28, 2025
    risk 0.55cvss 8.4epss 0.00

    UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-59236HigOct 14, 2025
    risk 0.55cvss 8.4epss 0.00

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-58299HigOct 11, 2025
    risk 0.55cvss 8.4epss 0.00

    Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-39882HigSep 23, 2025
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: fix potential OF node use-after-free The for_each_child_of_node() helper drops the reference it takes to each node as it iterates over children and an explicit of_node_put() is only needed when…

  • CVE-2023-53194HigSep 15, 2025
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add length check in indx_get_root This adds a length check to guarantee the retrieved index root is legit. [ 162.459513] BUG: KASAN: use-after-free in hdr_find_e.isra.0+0x10c/0x320 [ 162.460176]…

  • CVE-2025-22410HigAug 26, 2025
    risk 0.55cvss 8.4epss 0.00

    In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22409HigAug 26, 2025
    risk 0.55cvss 8.4epss 0.00

    In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22406HigAug 26, 2025
    risk 0.55cvss 8.4epss 0.00

    In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22405HigAug 26, 2025
    risk 0.55cvss 8.4epss 0.00

    In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22404HigAug 26, 2025
    risk 0.55cvss 8.4epss 0.00

    In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-53784HigAug 12, 2025
    risk 0.55cvss 8.4epss 0.00

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-53740HigAug 12, 2025
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-53731HigAug 12, 2025
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-27128HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

  • CVE-2025-24298HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.