VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,284)

page 15 of 415
  • CVE-2023-46850CriNov 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

  • CVE-2023-5175CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

  • CVE-2023-5174CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations…

  • CVE-2023-5172CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.

  • CVE-2023-39453CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.

  • CVE-2021-33390CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.01

    dpic 2021.04.10 has a use-after-free in thedeletestringbox() function in dpic.y. A different vulnerablility than CVE-2021-32421.

  • CVE-2023-30186CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.02

    A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

  • CVE-2023-38598CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary…

  • CVE-2022-48512CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally.

  • CVE-2022-48511CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally.

  • CVE-2021-46894CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation.

  • CVE-2023-32412CriJun 23, 2023
    risk 0.64cvss 9.8epss 0.02

    A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to cause…

  • CVE-2023-32387CriJun 23, 2023
    risk 0.64cvss 9.8epss 0.02

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.

  • CVE-2022-22630CriJun 23, 2023
    risk 0.64cvss 9.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.6, macOS Monterey 12.3, Security Update 2022-004 Catalina. A remote user may cause an unexpected app termination or arbitrary code execution

  • CVE-2023-21096CriApr 19, 2023
    risk 0.64cvss 9.8epss 0.00

    In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L…

  • CVE-2023-23392CriMar 14, 2023
    risk 0.64cvss 9.8epss 0.02

    HTTP Protocol Stack Remote Code Execution Vulnerability

  • CVE-2021-33391CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.

  • CVE-2022-46882CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.

  • CVE-2022-45406CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR <…

  • CVE-2022-34470CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.