VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,173)

page 374 of 409
  • CVE-2026-50425HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50414HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50413HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50410HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50406HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50404HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50403HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50398HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50397HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50396HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50393HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50392HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50385HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50379HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50374MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.

  • CVE-2026-50371HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50369HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50359HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50358HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50353HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.