VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,173)

page 342 of 409
  • CVE-2023-21601MedJan 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe Dimension version 3.4.6 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in…

  • CVE-2023-21598MedJan 13, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires…

  • CVE-2022-20552MedDec 16, 2022
    risk 0.36cvss 5.5epss 0.00

    In btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20502MedDec 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20496MedDec 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-42754MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.

  • CVE-2022-45146MedNov 21, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in…

  • CVE-2022-3636MedOct 21, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was identified in Linux Kernel 33fc42de33278b2b3ec6f3390512987bc29a62b7. This affects the function __mtk_ppe_check_skb of the file drivers/net/ethernet/mediatek/mtk_ppe.c of the component Ethernet Handler. Such manipulation leads to use after free. The name of…

  • CVE-2022-3620MedOct 20, 2022
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The name of the patch is…

  • CVE-2022-3534MedOct 17, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. Upgrading to version 5.10.163,…

  • CVE-2022-38437MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.03

    Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR.…

  • CVE-2022-38425MedSep 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2022-35709MedSep 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2022-38428MedSep 16, 2022
    risk 0.36cvss 5.5epss 0.00

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue…

  • CVE-2022-1204MedAug 29, 2022
    risk 0.36cvss 5.5epss 0.00

    A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the system.

  • CVE-2022-1184MedAug 29, 2022
    risk 0.36cvss 5.5epss 0.00

    A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service.

  • CVE-2021-4022MedAug 25, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially user controlled, depending on the build) memory address.

  • CVE-2022-36149MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    tifig v0.2.2 was discovered to contain a heap-use-after-free via temInfoEntry().

  • CVE-2022-35670MedAug 11, 2022
    risk 0.36cvss 5.5epss 0.02

    Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass…

  • CVE-2021-33468MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in yasm version 1.3.0. There is a use-after-free in error() in modules/preprocs/nasm/nasm-pp.c.