CWE-416
Use After Free
Description
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (8,192)
page 225 of 410| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46712 | Hig | 0.51 | 7.8 | 0.00 | Feb 27, 2023 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13. An app may be able to cause unexpected system termination or potentially execute code with kernel privileges. | ||
| CVE-2023-22246 | Hig | 0.51 | 7.8 | 0.00 | Feb 17, 2023 | Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2023-22244 | Hig | 0.51 | 7.8 | 0.00 | Feb 17, 2023 | Adobe Premiere Rush version 2.6 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2023-21808 | Hig | 0.51 | 7.8 | 0.01 | Feb 14, 2023 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-21822 | Hig | 0.51 | 7.8 | 0.01 | Feb 14, 2023 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2023-21688 | Hig | 0.51 | 7.8 | 0.04 | Feb 14, 2023 | NT OS Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-24581 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected application contains a use-after-free vulnerability that could be triggered while parsing… | ||
| CVE-2023-22360 | Hig | 0.51 | 7.8 | 0.00 | Feb 13, 2023 | Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information… | ||
| CVE-2023-20928 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2023 | In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android… | ||
| CVE-2023-20925 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2023 | In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-20920 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2023 | In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10… | ||
| CVE-2022-42374 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists… | ||
| CVE-2021-33641 | Hig | 0.51 | 7.8 | 0.00 | Jan 20, 2023 | When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free). | ||
| CVE-2023-21784 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21774 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-21773 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-21755 | Hig | 0.51 | 7.8 | 0.00 | Jan 10, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-21747 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-21735 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2023-21734 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Microsoft Office Remote Code Execution Vulnerability |
- risk 0.51cvss 7.8epss 0.00
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13. An app may be able to cause unexpected system termination or potentially execute code with kernel privileges.
- risk 0.51cvss 7.8epss 0.00
Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Adobe Premiere Rush version 2.6 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.01
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
NT OS Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected application contains a use-after-free vulnerability that could be triggered while parsing…
- risk 0.51cvss 7.8epss 0.00
Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information…
- risk 0.51cvss 7.8epss 0.00
In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…
- risk 0.51cvss 7.8epss 0.00
In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.51cvss 7.8epss 0.00
In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…
- risk 0.51cvss 7.8epss 0.00
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…
- risk 0.51cvss 7.8epss 0.00
When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability