CWE-416
Use After Free
Description
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (8,687)
page 425 of 435| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1071 | Hig | 0.00 | 8.2 | 0.01 | Mar 26, 2022 | User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2. | ||
| CVE-2022-1031 | Hig | 0.00 | 7.8 | 0.01 | Mar 22, 2022 | Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6. | ||
| CVE-2022-0849 | Med | 0.00 | 5.5 | 0.01 | Mar 5, 2022 | Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6. | ||
| CVE-2022-23308 | Hig | 0.00 | 7.5 | 0.05 | Feb 26, 2022 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | ||
| CVE-2022-23608 | Hig | 0.00 | 8.1 | 0.04 | Feb 22, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by… | ||
| CVE-2022-0559 | Cri | 0.00 | 9.8 | 0.01 | Feb 16, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. | ||
| CVE-2022-25139 | Cri | 0.00 | 9.8 | 0.02 | Feb 14, 2022 | njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. | ||
| CVE-2022-0523 | Hig | 0.00 | 7.8 | 0.01 | Feb 8, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. | ||
| CVE-2022-0520 | Hig | 0.00 | 7.8 | 0.01 | Feb 8, 2022 | Use After Free in NPM radare2.js prior to 5.6.2. | ||
| CVE-2022-0139 | Cri | 0.00 | 9.8 | 0.01 | Feb 8, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0. | ||
| CVE-2022-0487 | Med | 0.00 | 5.5 | 0.00 | Feb 4, 2022 | A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1. | ||
| CVE-2022-0443 | Hig | 0.00 | 7.8 | 0.01 | Feb 2, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-23597 | Hig | 0.00 | 8.3 | 0.01 | Feb 1, 2022 | Element Desktop is a Matrix client for desktop platforms with Element Web at its core. Element Desktop before 1.9.7 is vulnerable to a remote program execution bug with user interaction. The exploit is non-trivial and requires clicking on a malicious link, followed by another… | ||
| CVE-2022-0413 | Hig | 0.00 | 7.8 | 0.01 | Jan 30, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-24122 | Hig | 0.00 | 7.8 | 0.01 | Jan 29, 2022 | kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace. | ||
| CVE-2021-46022 | Med | 0.00 | 5.5 | 0.01 | Jan 14, 2022 | An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. | ||
| CVE-2022-0156 | Med | 0.00 | 5.5 | 0.02 | Jan 10, 2022 | vim is vulnerable to Use After Free | ||
| CVE-2021-46142 | Med | 0.00 | 5.5 | 0.01 | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. | ||
| CVE-2021-46141 | Med | 0.00 | 5.5 | 0.01 | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. | ||
| CVE-2015-6126 | 0.00 | — | 0.02 | Dec 9, 2015 | Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511… |
- risk 0.00cvss 8.2epss 0.01
User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
- risk 0.00cvss 7.8epss 0.01
Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.
- risk 0.00cvss 5.5epss 0.01
Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.
- risk 0.00cvss 7.5epss 0.05
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
- risk 0.00cvss 8.1epss 0.04
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by…
- risk 0.00cvss 9.8epss 0.01
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
- risk 0.00cvss 9.8epss 0.02
njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
- risk 0.00cvss 7.8epss 0.01
Use After Free in NPM radare2.js prior to 5.6.2.
- risk 0.00cvss 9.8epss 0.01
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.
- risk 0.00cvss 5.5epss 0.00
A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 8.3epss 0.01
Element Desktop is a Matrix client for desktop platforms with Element Web at its core. Element Desktop before 1.9.7 is vulnerable to a remote program execution bug with user interaction. The exploit is non-trivial and requires clicking on a malicious link, followed by another…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
- risk 0.00cvss 5.5epss 0.01
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
- risk 0.00cvss 5.5epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 5.5epss 0.01
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
- risk 0.00cvss 5.5epss 0.01
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
- CVE-2015-6126Dec 9, 2015risk 0.00cvss —epss 0.02
Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511…