VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 265 of 410
  • CVE-2025-12437HigNov 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-62788HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_event_for_log() references memory (initially allocated in OS_CleanMSG()) after it has been freed. A compromised agent can potentially compromise the integrity of…

  • CVE-2025-12105HigOct 23, 2025
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed…

  • CVE-2025-48008HigOct 15, 2025
    risk 0.49cvss 7.5epss 0.00

    When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of…

  • CVE-2025-55326HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-57616HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleaved method allows an attacker to cause a denial of service or memory corruption. The method violates Rust's aliasing rules by modifying a data structure through…

  • CVE-2025-46709HigAug 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kernel exception.

  • CVE-2025-52946HigJul 11, 2025
    risk 0.49cvss 7.5epss 0.00

    A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an attacker sending a BGP update with a specifically malformed AS PATH to cause rpd to crash, resulting in a Denial of Service (DoS).…

  • CVE-2025-49677HigJul 8, 2025
    risk 0.49cvss 7.0epss 0.01

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-1706HigMay 17, 2025
    risk 0.49cvss 7.5epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

  • CVE-2025-29831HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

  • CVE-2025-27578HigMay 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition.

  • CVE-2025-30194HigApr 29, 2025
    risk 0.49cvss 7.5epss 0.02

    When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched…

  • CVE-2025-26687HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-29815HigApr 4, 2025
    risk 0.49cvss 7.6epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

  • CVE-2025-1931HigMar 4, 2025
    risk 0.49cvss 7.5epss 0.01

    It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

  • CVE-2025-1012HigFeb 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

  • CVE-2025-21296HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.01

    BranchCache Remote Code Execution Vulnerability

  • CVE-2024-53185HigDec 27, 2024
    risk 0.49cvss 7.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: smb: client: fix NULL ptr deref in crypto_aead_setkey() Neither SMB3.0 or SMB3.02 supports encryption negotiate context, so when SMB2_GLOBAL_CAP_ENCRYPTION flag is set in the negotiate response, the client…

  • CVE-2024-38910HigDec 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2_amcl process. This vulnerability is triggered via sending a request to change dynamic parameters.