VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 236 of 410
  • CVE-2021-42721HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.04

    Acrobat Bridge versions 11.1.1 and earlier are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2021-42706HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer

  • CVE-2021-43275HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A Use After Free vulnerability exists in the DGN file reading procedure in Open Design Alliance Drawings SDK before 2022.8. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this…

  • CVE-2021-43274HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A Use After Free Vulnerability exists in the Open Design Alliance Drawings SDK before 2022.11. The specific flaw exists within the parsing of DWF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An…

  • CVE-2021-43412HigNov 7, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in GNU Hurd before 0.9 20210404-9. libports accepts fake notification messages from any client on any port, which can lead to port use-after-free. This can be exploited for local privilege escalation to get full root access.

  • CVE-2021-0936HigOct 25, 2021
    risk 0.51cvss 7.8epss 0.00

    In acc_read of f_accessory.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0483HigOct 22, 2021
    risk 0.51cvss 7.8epss 0.00

    In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2021-38438HigOct 18, 2021
    risk 0.51cvss 7.8epss 0.01

    A use after free vulnerability in FATEK Automation WinProladder versions 3.30 and prior may be exploited when a valid user opens a malformed project file, which may allow arbitrary code execution.

  • CVE-2021-40726HigOct 7, 2021
    risk 0.51cvss 7.8epss 0.05

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm field that could result in arbitrary code execution in the context of the current user.…

  • CVE-2021-40725HigOct 7, 2021
    risk 0.51cvss 7.8epss 0.05

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm listbox that could result in arbitrary code execution in the context of the current…

  • CVE-2021-0684HigOct 6, 2021
    risk 0.51cvss 7.8epss 0.00

    In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-41540HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process…

  • CVE-2021-41539HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process…

  • CVE-2021-41537HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process…

  • CVE-2021-41536HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process…

  • CVE-2021-41535HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could…

  • CVE-2021-0612HigSep 27, 2021
    risk 0.51cvss 7.8epss 0.00

    In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05425834.

  • CVE-2021-0611HigSep 27, 2021
    risk 0.51cvss 7.8epss 0.00

    In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05425810.

  • CVE-2021-38656HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.07

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2021-38655HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.06

    Microsoft Excel Remote Code Execution Vulnerability