VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,218)

page 150 of 411
  • CVE-2026-62711HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62707HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62701HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61934HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61357HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61349HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50061HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files.…

  • CVE-2026-50060HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files.…

  • CVE-2026-1289HigAug 6, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2026-17862HigJul 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)

  • CVE-2026-49743HigJul 24, 2026
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference…

  • CVE-2026-15905HigJul 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

  • CVE-2026-34196HigJul 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow and map two GPU virtual addresses to the same physical address. One of these virutal mappings can be freed along with the physical page, allowing for a…

  • CVE-2026-42958HigJul 7, 2026
    risk 0.51cvss 7.8epss 0.00

    The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This could allow an attacker to execute arbitrary code in the context of the current process.

  • CVE-2026-14094HigJun 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)

  • CVE-2026-14018HigJun 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)

  • CVE-2026-13844HigJun 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

  • CVE-2026-13827HigJun 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)

  • CVE-2026-13778HigJun 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)

  • CVE-2026-12921HigJun 25, 2026
    risk 0.51cvss 7.8epss 0.00

    In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.