VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 220 of 410
  • CVE-2023-36895HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2023-35382HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.06

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-35380HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.04

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-39549HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 2). The affected application contains a use-after-free vulnerability that could be triggered while parsing specially crafted DWG file. An attacker could leverage this vulnerability to execute…

  • CVE-2023-28830HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.2.0.5), Solid Edge SE2022 (All versions < V222.0 Update 13), Solid Edge SE2023 (All versions < V223.0 Update 4), Teamcenter Visualization V13.2 (All versions < V13.2.0.15), Teamcenter Visualization V13.3 (All…

  • CVE-2023-22277HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22317 and CVE-2023-22314.

  • CVE-2023-22317HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314.

  • CVE-2023-22314HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317.

  • CVE-2023-38748HigAug 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.

  • CVE-2023-4004HigJul 31, 2023
    risk 0.51cvss 7.8epss 0.01

    A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the…

  • CVE-2023-35993HigJul 27, 2023
    risk 0.51cvss 7.8epss 0.00

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to execute arbitrary…

  • CVE-2023-32433HigJul 27, 2023
    risk 0.51cvss 7.8epss 0.00

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to execute arbitrary…

  • CVE-2023-32381HigJul 27, 2023
    risk 0.51cvss 7.8epss 0.00

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.6.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-3609HigJul 21, 2023
    risk 0.51cvss 7.8epss 0.00

    A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in…

  • CVE-2023-21255HigJul 13, 2023
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-2763HigJul 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These vulnerabilities could allow an attacker to execute…

  • CVE-2023-2762HigJul 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A Use-After-Free vulnerability in SLDPRT file reading procedure exists in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file.

  • CVE-2023-35323HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows OLE Remote Code Execution Vulnerability

  • CVE-2023-35313HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability

  • CVE-2023-33149HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Graphics Remote Code Execution Vulnerability