CWE-416
8,553 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,553)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. |
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. |
Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network. |
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally. |
Use after free in Windows DNS allows an authorized attacker to execute code over a network. |
Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally. |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network. |
Use after free in DNS Server allows an unauthorized attacker to execute code over a network. |