VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,274)

page 132 of 414
  • CVE-2023-43546HigMar 4, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while invoking HGSL IOCTL context create.

  • CVE-2023-6143HigMar 4, 2024
    risk 0.55cvss 8.4epss 0.00

    Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper…

  • CVE-2021-47049HigFeb 28, 2024
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Use after free in __vmbus_open() The "open_info" variable is added to the &vmbus_connection.chn_msg_list, but the error handling frees "open_info" without removing it from the list. This…

  • CVE-2023-43514HigJan 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.

  • CVE-2023-33114HigJan 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.

  • CVE-2023-33108HigJan 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued.

  • CVE-2023-33094HigJan 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while running VK synchronization with KASAN enabled.

  • CVE-2023-36041HigNov 14, 2023
    risk 0.55cvss 7.8epss 0.57

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2023-33074HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Audio when SSR event is triggered after music playback is stopped.

  • CVE-2023-33039HigOct 3, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive Display while destroying the image handle created using connected display driver.

  • CVE-2023-33029HigOct 3, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in DSP Service during a remote call from HLOS to DSP.

  • CVE-2023-33021HigSep 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Graphics while processing user packets for command submission.

  • CVE-2023-21672HigJul 4, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions.

  • CVE-2022-25743HigNov 15, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2022-25723HigOct 19, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in multimedia due to use after free during callback registration failure in Snapdragon Mobile

  • CVE-2022-22077HigOct 19, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon Mobile

  • CVE-2022-22058HigSep 26, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2022-25693HigSep 16, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in graphics due to use-after-free while graphics profiling in Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2022-22095HigSep 16, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in synx driver due to use-after-free condition in the synx driver due to accessing object handles without acquiring lock in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2022-22097HigSep 2, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in graphic driver due to use after free while calling multiple threads application to driver. in Snapdragon Consumer IOT