CWE-416
Use After Free
Description
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (8,218)
page 144 of 411| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32589 | Hig | 0.53 | 8.1 | 0.09 | Dec 19, 2024 | A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiAnalyzer version… | ||
| CVE-2024-49132 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49128 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2024-49127 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2024-49126 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | ||
| CVE-2024-49118 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2024-49116 | Hig | 0.53 | 8.1 | 0.10 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49115 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49108 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49106 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-43703 | — | Hig | 0.53 | 8.1 | 0.00 | Nov 30, 2024 | Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads and writes of physical memory from the GPU HW. | |
| CVE-2024-43625 | Hig | 0.53 | 8.1 | 0.01 | Nov 12, 2024 | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | ||
| CVE-2024-6519 | Hig | 0.53 | 8.2 | 0.00 | Oct 21, 2024 | A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape. | ||
| CVE-2024-43582 | Hig | 0.53 | 8.1 | 0.03 | Oct 8, 2024 | Remote Desktop Protocol Server Remote Code Execution Vulnerability | ||
| CVE-2024-38229 | Hig | 0.53 | 8.1 | 0.02 | Oct 8, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2024-44068 | Hig | 0.53 | 8.1 | 0.01 | Oct 7, 2024 | An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation. | ||
| CVE-2024-46858 | Hig | 0.53 | 8.1 | 0.01 | Sep 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== net_rx_action … | ||
| CVE-2023-52885 | Hig | 0.53 | 8.1 | 0.01 | Jul 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock retaining a freed… | ||
| CVE-2024-35264 | Hig | 0.53 | 8.1 | 0.03 | Jul 9, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2024-37030 | Hig | 0.53 | 8.2 | 0.01 | Jul 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free. |
- risk 0.53cvss 8.1epss 0.09
A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiAnalyzer version…
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.10
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.00
Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads and writes of physical memory from the GPU HW.
- risk 0.53cvss 8.1epss 0.01
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
- risk 0.53cvss 8.2epss 0.00
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
- risk 0.53cvss 8.1epss 0.03
Remote Desktop Protocol Server Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.02
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.
- risk 0.53cvss 8.1epss 0.01
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== net_rx_action …
- risk 0.53cvss 8.1epss 0.01
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock retaining a freed…
- risk 0.53cvss 8.1epss 0.03
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.53cvss 8.2epss 0.01
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.