VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 225 of 410
  • CVE-2022-46712HigFeb 27, 2023
    risk 0.51cvss 7.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13. An app may be able to cause unexpected system termination or potentially execute code with kernel privileges.

  • CVE-2023-22246HigFeb 17, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-22244HigFeb 17, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Premiere Rush version 2.6 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2023-21808HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    .NET and Visual Studio Remote Code Execution Vulnerability

  • CVE-2023-21822HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2023-21688HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.04

    NT OS Kernel Elevation of Privilege Vulnerability

  • CVE-2023-24581HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected application contains a use-after-free vulnerability that could be triggered while parsing…

  • CVE-2023-22360HigFeb 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information…

  • CVE-2023-20928HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2023-20925HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-20920HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2022-42374HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…

  • CVE-2021-33641HigJan 20, 2023
    risk 0.51cvss 7.8epss 0.00

    When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).

  • CVE-2023-21784HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21774HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-21773HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-21755HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-21747HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-21735HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2023-21734HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Remote Code Execution Vulnerability