VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,218)

page 149 of 411
  • CVE-2021-21775HigJul 7, 2021
    risk 0.52cvss 8.0epss 0.01

    A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim…

  • CVE-2021-25370MedKEVMar 26, 2021
    risk 0.52cvss 6.1epss 0.01

    An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

  • CVE-2020-35898CriDec 31, 2020
    risk 0.52cvss 9.1epss 0.01

    An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more than one mutable reference to the same data.

  • CVE-2019-14586HigNov 23, 2020
    risk 0.52cvss 8.0epss 0.01

    Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.

  • CVE-2020-24430HigNov 5, 2020
    risk 0.52cvss 7.8epss 0.19

    Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a use-after-free vulnerability when handling malicious JavaScript. This vulnerability could result in arbitrary code execution in the context of…

  • CVE-2020-8856HigFeb 14, 2020
    risk 0.52cvss 7.8epss 0.20

    This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8846HigFeb 14, 2020
    risk 0.52cvss 7.8epss 0.20

    This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8845HigFeb 14, 2020
    risk 0.52cvss 7.8epss 0.19

    This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2019-13510HigAug 15, 2019
    risk 0.52cvss 7.8epss 0.12

    Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.

  • CVE-2018-16884HigDec 18, 2018
    risk 0.52cvss 8.0epss 0.01

    A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel…

  • CVE-2018-12863HigOct 12, 2018
    risk 0.52cvss 7.8epss 0.17

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2018-11130HigMay 17, 2018
    risk 0.52cvss 7.8epss 0.22

    The header::add_FORMAT_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted vcf file.

  • CVE-2017-1635HigDec 13, 2017
    risk 0.52cvss 8.0epss 0.03

    IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID:…

  • CVE-2017-5074HigOct 27, 2017
    risk 0.52cvss 8.0epss 0.01

    A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth.

  • CVE-2026-18299HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may…

  • CVE-2026-70311HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-65775HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.03

    Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65657HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-62888HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.02

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62779HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.