VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,284)

page 42 of 415
  • CVE-2020-6505CriJul 22, 2020
    risk 0.62cvss 9.6epss 0.01

    Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-6461CriMay 21, 2020
    risk 0.62cvss 9.6epss 0.01

    Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-6457CriMay 21, 2020
    risk 0.62cvss 9.6epss 0.01

    Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2019-5850CriNov 25, 2019
    risk 0.62cvss 9.6epss 0.01

    Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2019-5786MedKEVJun 27, 2019
    risk 0.62cvss 6.5epss 0.62

    Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2017-2985HigFeb 15, 2017
    risk 0.62cvss 8.8epss 0.22

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-2932HigJan 11, 2017
    risk 0.62cvss 8.8epss 0.25

    Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript MovieClip class. Successful exploitation could lead to arbitrary code execution.

  • CVE-2016-1013HigApr 9, 2016
    risk 0.62cvss 8.8epss 0.23

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011,…

  • CVE-2016-1011HigApr 9, 2016
    risk 0.62cvss 8.8epss 0.26

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013,…

  • CVE-2025-10729CriOct 3, 2025
    risk 0.61cvss epss 0.00

    The module will parse a node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free.

  • CVE-2025-47917HigJul 20, 2025
    risk 0.61cvss 8.9epss 0.02

    Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is documented as an output argument. The documentation does not…

  • CVE-2025-27038HigKEVJun 3, 2025
    risk 0.61cvss 7.5epss 0.01

    Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

  • CVE-2024-22267CriMay 14, 2024
    risk 0.61cvss 9.3epss 0.01

    VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

  • CVE-2024-22253CriMar 5, 2024
    risk 0.61cvss 9.3epss 0.01

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.…

  • CVE-2024-22252CriMar 5, 2024
    risk 0.61cvss 9.3epss 0.04

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.…

  • CVE-2019-5789HigMay 23, 2019
    risk 0.61cvss 8.8epss 0.09

    An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

  • CVE-2019-5788HigMay 23, 2019
    risk 0.61cvss 8.8epss 0.09

    An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

  • CVE-2018-4318HigApr 3, 2019
    risk 0.61cvss 8.8epss 0.09

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

  • CVE-2018-4317HigApr 3, 2019
    risk 0.61cvss 8.8epss 0.09

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

  • CVE-2018-4315HigApr 3, 2019
    risk 0.61cvss 8.8epss 0.09

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.