VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,277)

page 95 of 414
  • CVE-2023-1818HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-1815HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-1811HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1533HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1531HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.03

    Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1530HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1528HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-46394HigMar 8, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r39p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.

  • CVE-2023-1227HigMar 7, 2023
    risk 0.57cvss 8.8epss 0.00

    Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)

  • CVE-2023-1218HigMar 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1216HigMar 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1213HigMar 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-46395HigMar 6, 2023
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r0p0 through r32p0, Bifrost r0p0 through r41p0 before r42p0, Valhall r19p0 through r41p0…

  • CVE-2023-25363HigMar 2, 2023
    risk 0.57cvss 8.8epss 0.01

    A use-after-free vulnerability in WebCore::RenderLayer::updateDescendantDependentFlags in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

  • CVE-2023-25362HigMar 2, 2023
    risk 0.57cvss 8.8epss 0.01

    A use-after-free vulnerability in WebCore::RenderLayer::repaintBlockSelectionGaps in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

  • CVE-2023-25361HigMar 2, 2023
    risk 0.57cvss 8.8epss 0.01

    A use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

  • CVE-2023-25360HigMar 2, 2023
    risk 0.57cvss 8.8epss 0.01

    A use-after-free vulnerability in WebCore::RenderLayer::renderer in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

  • CVE-2023-25358HigMar 2, 2023
    risk 0.57cvss 8.8epss 0.01

    A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

  • CVE-2022-42826HigFeb 27, 2023
    risk 0.57cvss 8.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2023-0941HigFeb 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)