VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,277)

page 86 of 414
  • CVE-2024-40907CriJul 12, 2024
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic in XDP_TX action In the XDP_TX path, ionic driver sends a packet to the TX path with rx page and corresponding dma address. After tx is done, ionic_tx_clean() frees that page. But RX…

  • CVE-2024-38053HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability

  • CVE-2024-37320HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.02

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

  • CVE-2024-21332HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.02

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

  • CVE-2024-21308HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.02

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

  • CVE-2024-21303HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

  • CVE-2024-6293HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-6292HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-6291HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-6290HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-6103HigJun 20, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-5847HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

  • CVE-2024-5846HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

  • CVE-2024-5845HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

  • CVE-2024-5842HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-5841HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.05

    Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-5832HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-5831HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-5269HigJun 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this…

  • CVE-2024-5498HigMay 30, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)