VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,218)

page 158 of 411
  • CVE-2026-23010HigJan 25, 2026
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzbot reported use-after-free of inet6_ifaddr in inet6_addr_del(). [0] The cited commit accidentally moved ipv6_del_addr() for mngtmpaddr before reading its…

  • CVE-2025-71162HigJan 25, 2026
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-after-free bug exists in the Tegra ADMA driver when audio streams are terminated, particularly during XRUN conditions. The issue occurs when the DMA buffer is…

  • CVE-2026-22995HigJan 23, 2026
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ublk: fix use-after-free in ublk_partition_scan_work A race condition exists between the async partition scan work and device teardown that can lead to a use-after-free of ub->ub_disk: 1.…

  • CVE-2025-15062HigJan 23, 2026
    risk 0.51cvss 7.8epss 0.00

    Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target…

  • CVE-2025-13845HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

  • CVE-2025-71110HigJan 14, 2026
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: mm/slub: reset KASAN tag in defer_free() before accessing freed memory When CONFIG_SLUB_TINY is enabled, kfree_nolock() calls kasan_slab_free() before defer_free(). On ARM64 with MTE (Memory Tagging…

  • CVE-2026-21287HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-20950HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-20924HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20923HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20920HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20918HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20877HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20874HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20873HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20871HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.04

    Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20870HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20867HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20865HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20861HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.