VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,173)

page 344 of 409
  • CVE-2021-46501MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via SortSubCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46500MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ArgTypeCheck in src/jsiFunc.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46499MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueCopyMove in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46498MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_wswebsocketObjFree in src/jsiWebSocket.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46497MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_UserObjDelete in src/jsiUserObj.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46496MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_ObjFree in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46495MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via DeleteTreeValue in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46494MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueLookupBase in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46489MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_DecrRefCount in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46484MedJan 27, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_IncrRefCount in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46239MedJan 21, 2022
    risk 0.36cvss 5.5epss 0.01

    The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at utils/alloc.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2021-46169MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.01

    Modex v2.11 was discovered to contain an Use-After-Free vulnerability via the component tcache.

  • CVE-2021-46021MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.01

    An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

  • CVE-2021-45063MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.06

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could lead to disclosure of sensitive memory. An attacker could leverage…

  • CVE-2021-44713MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.03

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in application denial of service. Exploitation of this issue…

  • CVE-2021-36408MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265.

  • CVE-2021-41043MedJan 5, 2022
    risk 0.36cvss 5.5epss 0.01

    Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.

  • CVE-2021-45944MedJan 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).

  • CVE-2021-45263MedDec 22, 2021
    risk 0.36cvss 5.5epss 0.01

    An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmentation fault and application crash.

  • CVE-2021-45262MedDec 22, 2021
    risk 0.36cvss 5.5epss 0.01

    An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault and application crash.