VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,277)

page 99 of 414
  • CVE-2022-3046HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-3041HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-3039HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2859HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions.

  • CVE-2022-2858HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction.

  • CVE-2022-2855HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2852HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.03

    Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-22628HigSep 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2022-22624HigSep 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2022-36190CriAug 17, 2022
    risk 0.57cvss 9.8epss 0.01

    GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.

  • CVE-2022-2621HigAug 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Extensions in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.

  • CVE-2022-2614HigAug 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2613HigAug 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

  • CVE-2022-2606HigAug 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enable a specific Enterprise policy to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2604HigAug 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2603HigAug 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2399HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2481HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Views in Google Chrome prior to 103.0.5060.134 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via UI interaction.

  • CVE-2022-2478HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in PDF in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2477HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Guest View in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.