VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 228 of 410
  • CVE-2022-2896HigAug 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.

  • CVE-2022-1976HigAug 31, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable permission to create a string of requests that can cause a use-after-free flaw within the kernel. This issue leads to memory corruption and possible privilege…

  • CVE-2021-41785HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.02

    Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

  • CVE-2021-41784HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.01

    Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

  • CVE-2021-41783HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.02

    Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

  • CVE-2021-41782HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.02

    Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

  • CVE-2021-41781HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.02

    Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

  • CVE-2021-41780HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.01

    Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

  • CVE-2022-2978HigAug 24, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges…

  • CVE-2021-29117HigAug 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.

  • CVE-2022-20325HigAug 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In Media, there is a possible code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-186473060

  • CVE-2022-35675HigAug 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Adobe FrameMaker versions 2019 Update 8 (and earlier) and 2020 Update 4 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2022-35665HigAug 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-34263HigAug 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Adobe Illustrator versions 26.3.1 (and earlier) and 25.4.6 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-34707HigAug 9, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2022-34705HigAug 9, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Defender Credential Guard Elevation of Privilege Vulnerability

  • CVE-2022-1158HigAug 5, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the…

  • CVE-2021-33453HigJul 26, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.

  • CVE-2022-28683HigJul 18, 2022
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2022-28680HigJul 18, 2022
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…