VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,192)

page 323 of 410
  • CVE-2024-4741HigNov 13, 2024
    risk 0.42cvss 7.5epss 0.03

    Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution…

  • CVE-2024-47696HigOct 21, 2024
    risk 0.42cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency In the commit aee2424246f9 ("RDMA/iwcm: Fix a use-after-free related to destroying CM IDs"), the function flush_workqueue is invoked to…

  • CVE-2024-43570MedOct 8, 2024
    risk 0.42cvss 6.4epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-38235MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2024-8394MedSep 6, 2024
    risk 0.42cvss 6.5epss 0.00

    When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.

  • CVE-2024-40782MedJul 29, 2024
    risk 0.42cvss 6.5epss 0.01

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an…

  • CVE-2024-6777MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.00

    Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

  • CVE-2024-4949MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.01

    Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-4948MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.01

    Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-3759MedMay 7, 2024
    risk 0.42cvss 6.5epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.

  • CVE-2024-27217MedMay 7, 2024
    risk 0.42cvss 6.5epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

  • CVE-2023-35734MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this…

  • CVE-2023-34294MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this…

  • CVE-2023-32172MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Unified Automation UaGateway OPC UA Server Use-After-Free Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this…

  • CVE-2023-32135MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this…

  • CVE-2024-4060MedMay 1, 2024
    risk 0.42cvss 6.5epss 0.01

    Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-3914MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-26886MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: af_bluetooth: Fix deadlock Attemting to do sock_lock on .recvmsg may cause a deadlock as shown bellow, so instead of using sock_sock this uses sk_receive_queue.lock on bt_sock_ioctl to avoid the…

  • CVE-2024-3515MedApr 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-22098MedApr 2, 2024
    risk 0.42cvss 6.5epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.