VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,277)

page 84 of 414
  • CVE-2024-28888HigOct 2, 2024
    risk 0.57cvss 8.8epss 0.02

    A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code…

  • CVE-2024-23923HigSep 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Alpine Halo9 prh_l2_sar_data_ind Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. …

  • CVE-2024-9120HigSep 25, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2021-38023HigSep 23, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-8639HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-8638HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-8637HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-8636HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-38259HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft Management Console Remote Code Execution Vulnerability

  • CVE-2024-26186HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

  • CVE-2024-45063HigSep 5, 2024
    risk 0.57cvss 8.8epss 0.01

    The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the…

  • CVE-2024-8362HigSep 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-41160HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

  • CVE-2024-41157HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

  • CVE-2024-7968HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7964HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-7725HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2024-7724HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2024-7723HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2024-7536HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)