VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,687)

page 417 of 435
  • CVE-2022-1968HigJun 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1934HigMay 31, 2022
    risk 0.00cvss 7.8epss 0.00

    Use After Free in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2022-1898HigMay 27, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1796HigMay 19, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.4979.

  • CVE-2022-1795CriMay 18, 2022
    risk 0.00cvss 9.8epss 0.01

    Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

  • CVE-2022-1616HigMay 7, 2022
    risk 0.00cvss 7.8epss 0.03

    Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

  • CVE-2022-1516MedMay 5, 2022
    risk 0.00cvss 5.5epss 0.00

    A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality in the way a user terminates their session using a simulated Ethernet card and continued usage of this connection. This flaw allows a local user to crash…

  • CVE-2022-1195MedApr 29, 2022
    risk 0.00cvss 5.5epss 0.00

    A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or sixpack device is detached and reclaim resources early.

  • CVE-2022-1444MedApr 23, 2022
    risk 0.00cvss 5.5epss 0.01

    heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing denial of service.

  • CVE-2021-42779MedApr 18, 2022
    risk 0.00cvss 5.3epss 0.02

    A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.

  • CVE-2022-28042HigApr 15, 2022
    risk 0.00cvss 8.8epss 0.02

    stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.

  • CVE-2022-27007CriApr 14, 2022
    risk 0.00cvss 9.8epss 0.02

    nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save().

  • CVE-2022-28893HigApr 11, 2022
    risk 0.00cvss 7.8epss 0.00

    The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.

  • CVE-2022-1284MedApr 8, 2022
    risk 0.00cvss 5.5epss 0.01

    heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

  • CVE-2022-1212CriApr 5, 2022
    risk 0.00cvss 9.8epss 0.02

    Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

  • CVE-2022-1154HigMar 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

  • CVE-2022-1106CriMar 27, 2022
    risk 0.00cvss 9.1epss 0.01

    use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2022-1071HigMar 26, 2022
    risk 0.00cvss 8.2epss 0.01

    User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2021-4203MedMar 25, 2022
    risk 0.00cvss 6.8epss 0.02

    A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.

  • CVE-2021-4202HigMar 25, 2022
    risk 0.00cvss 7.0epss 0.00

    A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to a privilege…