VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 268 of 410
  • CVE-2023-28319HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.02

    A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now…

  • CVE-2023-2135HigApr 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-43716HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl.…

  • CVE-2022-48340HigFeb 21, 2023
    risk 0.49cvss 7.5epss 0.01

    In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.

  • CVE-2022-30539HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.00

    Use after free in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-40016HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in librtmp, allows attackers to cause a denial of service.

  • CVE-2023-0215HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.04

    The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function…

  • CVE-2022-45407HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    If an attacker loaded a font using FontFace() on a background worker, a use-after-free could have occurred, leading to a potentially exploitable crash. This vulnerability affects Firefox < 107.

  • CVE-2022-38476HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A data race could occur in the PK11_ChangePW function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.

  • CVE-2022-46311HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.

  • CVE-2022-35254HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.03

    An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust…

  • CVE-2022-44550HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-44547HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.

  • CVE-2022-39823HigOct 20, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the server limit on continuation points may cause a use-after-free error

  • CVE-2022-40278HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_free after sqlite3_exec, leading to a denial of service.

  • CVE-2022-2738HigSep 1, 2022
    risk 0.49cvss 7.5epss 0.01

    The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause…

  • CVE-2022-0934HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.02

    A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service.

  • CVE-2022-34568HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.

  • CVE-2022-1487HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via running a Wayland test.

  • CVE-2022-1485HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.