CWE-416
Use After Free
Description
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (8,173)
page 392 of 409| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1154 | Hig | 0.00 | 7.8 | 0.01 | Mar 30, 2022 | Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. | ||
| CVE-2022-1106 | Cri | 0.00 | 9.1 | 0.01 | Mar 27, 2022 | use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2. | ||
| CVE-2022-1071 | Hig | 0.00 | 8.2 | 0.01 | Mar 26, 2022 | User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2. | ||
| CVE-2021-4203 | Med | 0.00 | 6.8 | 0.02 | Mar 25, 2022 | A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information. | ||
| CVE-2021-4202 | Hig | 0.00 | 7.0 | 0.00 | Mar 25, 2022 | A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to a privilege… | ||
| CVE-2021-3748 | Hig | 0.00 | 7.5 | 0.01 | Mar 23, 2022 | A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to… | ||
| CVE-2022-1031 | Hig | 0.00 | 7.8 | 0.01 | Mar 22, 2022 | Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6. | ||
| CVE-2021-45868 | Med | 0.00 | 5.5 | 0.01 | Mar 18, 2022 | In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file. | ||
| CVE-2022-0849 | Med | 0.00 | 5.5 | 0.01 | Mar 5, 2022 | Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6. | ||
| CVE-2021-3640 | Hig | 0.00 | 7.0 | 0.00 | Mar 3, 2022 | A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable… | ||
| CVE-2021-3715 | Hig | 0.00 | 7.8 | 0.00 | Mar 2, 2022 | A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their… | ||
| CVE-2022-23308 | Hig | 0.00 | 7.5 | 0.06 | Feb 26, 2022 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | ||
| CVE-2021-3700 | Med | 0.00 | 6.4 | 0.00 | Feb 24, 2022 | A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination. | ||
| CVE-2021-43826 | Hig | 0.00 | 7.5 | 0.01 | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:`upstream tunneling <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_config>` and the… | ||
| CVE-2021-43825 | Med | 0.00 | 6.1 | 0.01 | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. Sending a locally generated response must stop further processing of request or response data. Envoy tracks the amount of buffered request and response data and aborts the request if the… | ||
| CVE-2022-23608 | Hig | 0.00 | 8.1 | 0.04 | Feb 22, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by… | ||
| CVE-2022-0559 | Cri | 0.00 | 9.8 | 0.01 | Feb 16, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. | ||
| CVE-2022-25139 | Cri | 0.00 | 9.8 | 0.02 | Feb 14, 2022 | njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. | ||
| CVE-2022-0523 | Hig | 0.00 | 7.8 | 0.01 | Feb 8, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. | ||
| CVE-2022-0520 | Hig | 0.00 | 7.8 | 0.01 | Feb 8, 2022 | Use After Free in NPM radare2.js prior to 5.6.2. |
- risk 0.00cvss 7.8epss 0.01
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
- risk 0.00cvss 9.1epss 0.01
use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
- risk 0.00cvss 8.2epss 0.01
User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
- risk 0.00cvss 6.8epss 0.02
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.
- risk 0.00cvss 7.0epss 0.00
A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to a privilege…
- risk 0.00cvss 7.5epss 0.01
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to…
- risk 0.00cvss 7.8epss 0.01
Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.
- risk 0.00cvss 5.5epss 0.01
In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file.
- risk 0.00cvss 5.5epss 0.01
Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.
- risk 0.00cvss 7.0epss 0.00
A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable…
- risk 0.00cvss 7.8epss 0.00
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their…
- risk 0.00cvss 7.5epss 0.06
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
- risk 0.00cvss 6.4epss 0.00
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
- risk 0.00cvss 7.5epss 0.01
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:`upstream tunneling <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_config>` and the…
- risk 0.00cvss 6.1epss 0.01
Envoy is an open source edge and service proxy, designed for cloud-native applications. Sending a locally generated response must stop further processing of request or response data. Envoy tracks the amount of buffered request and response data and aborts the request if the…
- risk 0.00cvss 8.1epss 0.04
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by…
- risk 0.00cvss 9.8epss 0.01
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
- risk 0.00cvss 9.8epss 0.02
njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
- risk 0.00cvss 7.8epss 0.01
Use After Free in NPM radare2.js prior to 5.6.2.