VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,687)

page 425 of 435
  • CVE-2022-1071HigMar 26, 2022
    risk 0.00cvss 8.2epss 0.01

    User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2022-1031HigMar 22, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.

  • CVE-2022-0849MedMar 5, 2022
    risk 0.00cvss 5.5epss 0.01

    Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

  • CVE-2022-23308HigFeb 26, 2022
    risk 0.00cvss 7.5epss 0.05

    valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

  • CVE-2022-23608HigFeb 22, 2022
    risk 0.00cvss 8.1epss 0.04

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by…

  • CVE-2022-0559CriFeb 16, 2022
    risk 0.00cvss 9.8epss 0.01

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-25139CriFeb 14, 2022
    risk 0.00cvss 9.8epss 0.02

    njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.

  • CVE-2022-0523HigFeb 8, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-0520HigFeb 8, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in NPM radare2.js prior to 5.6.2.

  • CVE-2022-0139CriFeb 8, 2022
    risk 0.00cvss 9.8epss 0.01

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

  • CVE-2022-0487MedFeb 4, 2022
    risk 0.00cvss 5.5epss 0.00

    A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1.

  • CVE-2022-0443HigFeb 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-23597HigFeb 1, 2022
    risk 0.00cvss 8.3epss 0.01

    Element Desktop is a Matrix client for desktop platforms with Element Web at its core. Element Desktop before 1.9.7 is vulnerable to a remote program execution bug with user interaction. The exploit is non-trivial and requires clicking on a malicious link, followed by another…

  • CVE-2022-0413HigJan 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-24122HigJan 29, 2022
    risk 0.00cvss 7.8epss 0.01

    kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

  • CVE-2021-46022MedJan 14, 2022
    risk 0.00cvss 5.5epss 0.01

    An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

  • CVE-2022-0156MedJan 10, 2022
    risk 0.00cvss 5.5epss 0.02

    vim is vulnerable to Use After Free

  • CVE-2021-46142MedJan 6, 2022
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

  • CVE-2021-46141MedJan 6, 2022
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

  • CVE-2015-6126Dec 9, 2015
    risk 0.00cvss —epss 0.02

    Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511…