VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,284)

page 16 of 415
  • CVE-2022-31747CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have…

  • CVE-2022-38983CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may result in arbitrary code execution.

  • CVE-2022-40009CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.

  • CVE-2022-20122CriAug 24, 2022
    risk 0.64cvss 9.8epss 0.00

    The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid…

  • CVE-2021-39815CriAug 24, 2022
    risk 0.64cvss 9.8epss 0.00

    The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid…

  • CVE-2022-35164CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.01

    LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.

  • CVE-2022-21806CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.

  • CVE-2022-28350CriMay 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-after-free situation.

  • CVE-2022-28349CriMay 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p0 through r23p0 before r24p0.

  • CVE-2022-28348CriMay 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.

  • CVE-2022-29794CriMay 13, 2022
    risk 0.64cvss 9.8epss 0.01

    The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.

  • CVE-2022-22641CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

  • CVE-2021-37045CriDec 8, 2021
    risk 0.64cvss 9.8epss 0.01

    There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart unexpectedly and the kernel-mode code to be executed.

  • CVE-2021-1976CriSep 17, 2021
    risk 0.64cvss 9.8epss 0.01

    A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…

  • CVE-2021-1864CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.02

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An attacker with JavaScript execution may be able to execute arbitrary code.

  • CVE-2021-22390CriAug 2, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.

  • CVE-2021-22348CriJun 30, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause code to execute.

  • CVE-2021-27649CriJun 23, 2021
    risk 0.64cvss 9.8epss 0.02

    Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2021-0516CriJun 21, 2021
    risk 0.64cvss 9.8epss 0.02

    In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-23302CriJun 10, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0