VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,173)

page 370 of 409
  • CVE-2026-64703CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.

  • CVE-2026-64700CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-43822CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-43814CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-43812CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-43810CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or…

  • CVE-2026-43799CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-43778CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination…

  • CVE-2026-28928CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-13071MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.

  • CVE-2026-60080HigJul 21, 2026
    risk 0.00cvss 7.3epss 0.00

    Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to…

  • CVE-2026-58598HigJul 16, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55406MedJul 16, 2026
    risk 0.00cvss epss 0.00

    Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the OwnedView type allowed safe Rust code to trigger a use-after-free: the OwnedView::decode constructor transmuted a borrowed slice to &'static…

  • CVE-2026-6424MedJul 16, 2026
    risk 0.00cvss epss 0.00

    Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system

  • CVE-2026-15774HigJul 14, 2026
    risk 0.00cvss 8.3epss 0.00

    Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15773CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.00

    Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15772HigJul 14, 2026
    risk 0.00cvss 8.3epss 0.00

    Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-15765HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-15764HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-58637HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.