VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,173)

page 341 of 409
  • CVE-2023-4133MedAug 3, 2023
    risk 0.36cvss 5.5epss 0.00

    A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of…

  • CVE-2023-4132MedAug 3, 2023
    risk 0.36cvss 5.5epss 0.00

    A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service condition.

  • CVE-2023-39129MedJul 25, 2023
    risk 0.36cvss 5.5epss 0.00

    GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c.

  • CVE-2023-28469MedJun 2, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before…

  • CVE-2023-31518MedMay 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A heap use-after-free in the component CDataFileReader::GetItem of teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via a crafted map file.

  • CVE-2023-31725MedMay 17, 2023
    risk 0.36cvss 5.5epss 0.00

    yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at yasm/modules/preprocs/nasm/nasm-pp.c.

  • CVE-2023-31974MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    yasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.

  • CVE-2023-31972MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    yasm v1.3.0 was discovered to contain a use after free via the function pp_getline at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.

  • CVE-2023-2162MedApr 19, 2023
    risk 0.36cvss 5.5epss 0.00

    A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux Kernel. In this flaw an attacker could leak kernel internal information.

  • CVE-2023-28980MedApr 17, 2023
    risk 0.36cvss 5.5epss 0.00

    A Use After Free vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause Denial of Service (DoS). In a rib sharding scenario the rpd process will crash shortly after…

  • CVE-2022-37382MedMar 29, 2023
    risk 0.36cvss 5.5epss 0.01

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…

  • CVE-2022-37379MedMar 29, 2023
    risk 0.36cvss 5.5epss 0.01

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…

  • CVE-2023-26349MedMar 28, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in…

  • CVE-2023-1249MedMar 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A use-after-free flaw was found in the Linux kernel’s core dump subsystem. This flaw allows a local user to crash the system. Only if patch 390031c94211 ("coredump: Use the vma snapshot in fill_files_note") not applied yet, then kernel could be affected.

  • CVE-2022-47460MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In gpu device, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.

  • CVE-2023-21584MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2022-47371MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In bt driver, there is a thread competition leads to early release of resources to be accessed. This could lead to local denial of service in kernel.

  • CVE-2023-0469MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.

  • CVE-2022-42414MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2022-42408MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…