VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,218)

page 146 of 411
  • CVE-2023-23404HigMar 14, 2023
    risk 0.53cvss 8.1epss 0.01

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

  • CVE-2023-21679HigJan 10, 2023
    risk 0.53cvss 8.1epss 0.01

    Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

  • CVE-2022-23459HigAug 19, 2022
    risk 0.53cvss 8.1epss 0.01

    Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value class may lead to memory corruption via a double free or via a use after free. The value class has a default assignment operator which may be used with pointer…

  • CVE-2022-32293HigAug 3, 2022
    risk 0.53cvss 8.1epss 0.02

    In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.

  • CVE-2021-3750HigMay 2, 2022
    risk 0.53cvss 8.2epss 0.01

    A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions…

  • CVE-2021-21772HigMar 10, 2021
    risk 0.53cvss 8.1epss 0.04

    A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2020-25632HigMar 3, 2021
    risk 0.53cvss 8.2epss 0.01

    A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed…

  • CVE-2020-8265HigJan 6, 2021
    risk 0.53cvss 8.1epss 0.09

    Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If…

  • CVE-2020-35874HigDec 31, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the internment crate through 2020-05-28 for Rust. ArcIntern::drop has a race condition and resultant use-after-free.

  • CVE-2020-4004HigNov 20, 2020
    risk 0.53cvss 8.2epss 0.00

    VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local…

  • CVE-2020-3962HigJun 24, 2020
    risk 0.53cvss 8.2epss 0.01

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious actor with local…

  • CVE-2020-12387HigMay 26, 2020
    risk 0.53cvss 8.1epss 0.01

    A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

  • CVE-2020-2758HigApr 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the…

  • CVE-2018-21040HigApr 8, 2020
    risk 0.53cvss 8.1epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is a race condition with a resultant use-after-free in the g2d driver. The Samsung ID is SVE-2018-12959 (December 2018).

  • CVE-2018-21085HigApr 8, 2020
    risk 0.53cvss 8.1epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant use-after-free in vnswap_deinit_backing_storage. The Samsung ID is SVE-2017-11176 (February 2018).

  • CVE-2018-21084HigApr 8, 2020
    risk 0.53cvss 8.1epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition with a resultant read-after-free issue in get_kek. The Samsung ID is SVE-2017-11174 (February 2018).

  • CVE-2019-20568HigMar 24, 2020
    risk 0.53cvss 8.1epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos and Qualcomm chipsets) software. A race condition causes a Use-After-Free. The Samsung ID is SVE-2019-15067 (September 2019).

  • CVE-2020-6208HigMar 10, 2020
    risk 0.53cvss 8.2epss 0.01

    SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to…

  • CVE-2018-1311HigDec 18, 2019
    risk 0.53cvss 8.1epss 0.10

    The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be…

  • CVE-2019-19770HigDec 12, 2019
    risk 0.53cvss 8.2epss 0.02

    In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_create_file). NOTE:…