VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 318 of 410
  • CVE-2023-28307MedApr 11, 2023
    risk 0.43cvss 6.6epss 0.01

    Windows DNS Server Remote Code Execution Vulnerability

  • CVE-2023-28306MedApr 11, 2023
    risk 0.43cvss 6.6epss 0.01

    Windows DNS Server Remote Code Execution Vulnerability

  • CVE-2023-28305MedApr 11, 2023
    risk 0.43cvss 6.6epss 0.01

    Windows DNS Server Remote Code Execution Vulnerability

  • CVE-2023-28223MedApr 11, 2023
    risk 0.43cvss 6.6epss 0.01

    Windows Domain Name Service Remote Code Execution Vulnerability

  • CVE-2019-7075MedMay 24, 2019
    risk 0.43cvss 6.5epss 0.04

    Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2019-7136MedMay 23, 2019
    risk 0.43cvss 6.5epss 0.04

    Adobe Bridge CC versions 9.0.2 have an use after free vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2019-7823MedMay 22, 2019
    risk 0.43cvss 6.5epss 0.10

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful…

  • CVE-2019-7821MedMay 22, 2019
    risk 0.43cvss 6.5epss 0.10

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to…

  • CVE-2019-7809MedMay 22, 2019
    risk 0.43cvss 6.5epss 0.10

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to…

  • CVE-2019-7785MedMay 22, 2019
    risk 0.43cvss 6.5epss 0.10

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to…

  • CVE-2019-6556MedApr 10, 2019
    risk 0.43cvss 6.6epss 0.01

    When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the…

  • CVE-2019-6734MedMar 21, 2019
    risk 0.43cvss 6.5epss 0.04

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2018-16841MedNov 28, 2018
    risk 0.43cvss 6.5epss 0.05

    Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card authentication, Samba's KDC will call talloc_free() twice on the same memory if the principal in a validly signed certificate does not…

  • CVE-2018-11412MedMay 24, 2018
    risk 0.43cvss 5.9epss 0.16

    In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode.

  • CVE-2017-16648MedNov 7, 2017
    risk 0.43cvss 6.6epss 0.00

    The dvb_frontend_free function in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device. NOTE: the function…

  • CVE-2017-16528MedNov 4, 2017
    risk 0.43cvss 6.6epss 0.00

    sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (snd_rawmidi_dev_seq_free use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16527MedNov 4, 2017
    risk 0.43cvss 6.6epss 0.00

    sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.

  • CVE-2017-16525MedNov 4, 2017
    risk 0.43cvss 6.6epss 0.00

    The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device, related to…

  • CVE-2017-11232MedAug 11, 2017
    risk 0.43cvss 6.5epss 0.08

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful…

  • CVE-2010-0629MedApr 7, 2010
    risk 0.43cvss 6.5epss 0.05

    Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.