VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,687)

page 419 of 435
  • CVE-2022-0413HigJan 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-24122HigJan 29, 2022
    risk 0.00cvss 7.8epss 0.01

    kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

  • CVE-2021-4083HigJan 18, 2022
    risk 0.00cvss 7.0epss 0.00

    A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or…

  • CVE-2021-46022MedJan 14, 2022
    risk 0.00cvss 5.5epss 0.01

    An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

  • CVE-2021-40566MedJan 12, 2022
    risk 0.00cvss 5.5epss 0.01

    A Segmentation fault casued by heap use after free vulnerability exists in Gpac through 1.0.1 via the mpgviddmx_process function in reframe_mpgvid.c when using mp4box, which causes a denial of service.

  • CVE-2022-0156MedJan 10, 2022
    risk 0.00cvss 5.5epss 0.02

    vim is vulnerable to Use After Free

  • CVE-2021-46142MedJan 6, 2022
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

  • CVE-2021-46141MedJan 6, 2022
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

  • CVE-2021-4192HigDec 31, 2021
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Use After Free

  • CVE-2021-4187HigDec 29, 2021
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Use After Free

  • CVE-2021-4173HigDec 27, 2021
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Use After Free

  • CVE-2021-45701CriDec 27, 2021
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A patch operation may result in a use-after-free.

  • CVE-2021-4069HigDec 6, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Use After Free

  • CVE-2021-3962HigNov 19, 2021
    risk 0.00cvss 7.8epss 0.06

    A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest…

  • CVE-2021-3974HigNov 19, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Use After Free

  • CVE-2021-43400CriNov 4, 2021
    risk 0.00cvss 9.1epss 0.02

    An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.

  • CVE-2021-43057HigOct 28, 2021
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel before 5.14.8. A use-after-free in selinux_ptrace_traceme (aka the SELinux handler for PTRACE_TRACEME) could be used by local attackers to cause memory corruption and escalate privileges, aka CID-a3727a8bac0a. This occurs because of an…

  • CVE-2020-22617CriOct 8, 2021
    risk 0.00cvss 9.8epss 0.01

    Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.

  • CVE-2020-21913MedSep 20, 2021
    risk 0.00cvss 5.5epss 0.01

    International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.

  • CVE-2021-3796HigSep 15, 2021
    risk 0.00cvss 7.3epss 0.02

    vim is vulnerable to Use After Free