VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 285 of 410
  • CVE-2025-59216HigSep 18, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59215HigSep 18, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-10527HigSep 16, 2025
    risk 0.46cvss 7.1epss 0.00

    Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

  • CVE-2025-55223HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54112HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54108HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54105HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53807HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53802HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-38584HigAug 19, 2025
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in padata_reorder that goes back to the initial commit. A reference count is taken at the start of the process in padata_do_parallel, and…

  • CVE-2025-53721HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53718HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53147HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53142HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53140HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53137HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50167HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-23281HigAug 2, 2025
    risk 0.46cvss 7.0epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race condition might be able to trigger a use-after-free error. A successful exploit of this vulnerability might lead to code execution, escalation of…

  • CVE-2025-49699HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-49685HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.