VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,889)

page 74 of 95
  • CVE-2017-7946MedApr 18, 2017
    risk 0.36cvss 5.5epss 0.00

    The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file.

  • CVE-2016-10217MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.01

    The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file that is mishandled in the color management module.

  • CVE-2016-3179MedMar 24, 2017
    risk 0.36cvss 5.5epss 0.00

    The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (invalid free and daemon crash) via vectors related to error handling.

  • CVE-2017-6966MedMar 17, 2017
    risk 0.36cvss 5.5epss 0.00

    readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.

  • CVE-2017-5666MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.00

    The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a crafted file.

  • CVE-2016-4488MedFeb 24, 2017
    risk 0.36cvss 5.5epss 0.00

    Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "ktypevec."

  • CVE-2016-4487MedFeb 24, 2017
    risk 0.36cvss 5.5epss 0.00

    Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec."

  • CVE-2016-8674MedFeb 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.

  • CVE-2016-5824MedJan 27, 2017
    risk 0.36cvss 5.5epss 0.00

    libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.

  • CVE-2016-5823MedJan 27, 2017
    risk 0.36cvss 5.5epss 0.00

    The icalproperty_new_clone function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.

  • CVE-2016-9401MedJan 23, 2017
    risk 0.36cvss 5.5epss 0.00

    popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.

  • CVE-2016-7906MedJan 18, 2017
    risk 0.36cvss 5.5epss 0.00

    magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.

  • CVE-2016-9923MedDec 23, 2016
    risk 0.36cvss 5.5epss 0.00

    Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging the device in the guest. A guest user/process could use this flaw to crash a Qemu process on the host resulting in DoS.

  • CVE-2016-6265MedSep 22, 2016
    risk 0.36cvss 5.5epss 0.00

    Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

  • CVE-2026-4390MedMay 27, 2026
    risk 0.35cvss 5.4epss 0.00

    A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the component Connection State Management. This manipulation causes use after free. The attack may be initiated remotely. Upgrading to version 3.13.8 is able to…

  • CVE-2026-41401MedMay 26, 2026
    risk 0.35cvss 6.5epss 0.00

    libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents…

  • CVE-2026-5460MedApr 10, 2026
    risk 0.35cvss 6.5epss 0.00

    A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the error handling path of TLSX_KeyShare_ProcessPqcHybridClient() in src/tls.c, the inner function TLSX_KeyShare_ProcessPqcClient_ex() frees a KyberKey object upon…

  • CVE-2026-4752MedMar 24, 2026
    risk 0.35cvss 6.4epss 0.00

    Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329.

  • CVE-2026-4271MedMar 17, 2026
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This…

  • CVE-2026-2804MedFeb 24, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.