VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 283 of 410
  • CVE-2026-20842HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20830HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-20779HigJan 6, 2026
    risk 0.46cvss 7.0epss 0.00

    In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184084; Issue ID: MSV-4720.

  • CVE-2025-48769HigJan 1, 2026
    risk 0.46cvss 8.1epss 0.02

    Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to the previously freed…

  • CVE-2025-62573HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62569HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62555HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-62213HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.02

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60717HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60716HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59515HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59282HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-59221HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-59202HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59196HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59195HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.

  • CVE-2025-58738HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-58737HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

  • CVE-2025-58736HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-58735HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.