VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,218)

page 144 of 411
  • CVE-2021-32589HigDec 19, 2024
    risk 0.53cvss 8.1epss 0.09

    A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiAnalyzer version…

  • CVE-2024-49132HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49128HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

  • CVE-2024-49127HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2024-49126HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

  • CVE-2024-49118HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2024-49116HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.10

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49115HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49108HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49106HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-43703HigNov 30, 2024
    risk 0.53cvss 8.1epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads and writes of physical memory from the GPU HW.

  • CVE-2024-43625HigNov 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Microsoft Windows VMSwitch Elevation of Privilege Vulnerability

  • CVE-2024-6519HigOct 21, 2024
    risk 0.53cvss 8.2epss 0.00

    A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

  • CVE-2024-43582HigOct 8, 2024
    risk 0.53cvss 8.1epss 0.03

    Remote Desktop Protocol Server Remote Code Execution Vulnerability

  • CVE-2024-38229HigOct 8, 2024
    risk 0.53cvss 8.1epss 0.02

    .NET and Visual Studio Remote Code Execution Vulnerability

  • CVE-2024-44068HigOct 7, 2024
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2024-46858HigSep 27, 2024
    risk 0.53cvss 8.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== net_rx_action …

  • CVE-2023-52885HigJul 14, 2024
    risk 0.53cvss 8.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock retaining a freed…

  • CVE-2024-35264HigJul 9, 2024
    risk 0.53cvss 8.1epss 0.03

    .NET and Visual Studio Remote Code Execution Vulnerability

  • CVE-2024-37030HigJul 2, 2024
    risk 0.53cvss 8.2epss 0.01

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.