VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,173)

page 340 of 409
  • CVE-2021-46930MedFeb 27, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: usb: mtu3: fix list_head check warning This is caused by uninitialization of list_head. BUG: KASAN: use-after-free in __list_del_entry_valid+0x34/0xe4 Call trace: dump_backtrace+0x0/0x298…

  • CVE-2024-25763MedFeb 26, 2024
    risk 0.36cvss 5.5epss 0.00

    openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.

  • CVE-2024-20734MedFeb 15, 2024
    risk 0.36cvss 5.5epss 0.03

    Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…

  • CVE-2024-23848MedJan 23, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.

  • CVE-2024-22914MedJan 19, 2024
    risk 0.36cvss 5.5epss 0.00

    A heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620. It allows an attacker to cause denial of service.

  • CVE-2023-5091MedJan 8, 2024
    risk 0.36cvss 5.5epss 0.00

    Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r37p0 through r40p0.

  • CVE-2023-49554MedJan 3, 2024
    risk 0.36cvss 5.5epss 0.00

    Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.

  • CVE-2023-42365MedNov 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.

  • CVE-2023-42364MedNov 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.

  • CVE-2023-42363MedNov 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.

  • CVE-2023-44328MedNov 16, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2023-44361MedNov 16, 2023
    risk 0.36cvss 5.5epss 0.02

    Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR.…

  • CVE-2023-4891MedNov 8, 2023
    risk 0.36cvss 5.5epss 0.00

    A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service.

  • CVE-2023-46362MedNov 8, 2023
    risk 0.36cvss 5.5epss 0.00

    jbig2enc v0.28 was discovered to contain a heap-use-after-free via jbig2enc_auto_threshold_using_hash in src/jbig2enc.cc.

  • CVE-2023-44323MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.01

    Adobe Acrobat for Edge version 118.0.2088.46 (and earlier) is affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue…

  • CVE-2023-38216MedOct 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2023-38160MedSep 12, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows TCP/IP Information Disclosure Vulnerability

  • CVE-2023-41000MedSep 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c.

  • CVE-2021-40790MedSep 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2021-39859MedSep 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass…