CWE-416
7,441 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (7,441)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it. |
3Fedoraproject Libemf ProjectOpensuse3Fedora LeapLibemfNov 21, 2024 May 11, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free. |
2Canonical Iproute2 Project2Iproute2 Ubuntu LinuxNov 21, 2024 May 9, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option of...Show more |
6Canonical DebianLinux+3 more22Active Iq Unified Manager Debian LinuxElement Software+19 moreNov 21, 2024 May 8, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /d...Show more |
An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body. |
3Fedoraproject OpensuseSamba3Fedora LeapSambaNov 21, 2024 May 4, 2020 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This...Show more |
4Canonical DebianGnu+1 more8Active Iq Unified Manager Debian LinuxGlibc+5 moreNov 21, 2024 Apr 30, 2020 N/A· v4 7.0 HIGH· v3 3.7 LOW· v2 A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by...Show more |
2Linux Netapp10Active Iq Unified Manager Aff A700sCloud Backup+7 moreNov 21, 2024 Apr 29, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925. |
2Freebsd Netapp2Clustered Data Ontap FreebsdNov 21, 2024 Apr 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in memory access after it has...Show more |
setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock. |
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7...Show more |
1Foxitsoftware 2Phantompdf ReaderNov 21, 2024 Apr 22, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malic...Show more |
1Foxitsoftware 2Phantompdf ReaderNov 21, 2024 Apr 22, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malic...Show more |
1Foxitsoftware 2Phantompdf ReaderNov 21, 2024 Apr 22, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malic...Show more |
1Foxitsoftware 2Phantompdf ReaderNov 21, 2024 Apr 22, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malic...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Apr 22, 2020 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service. |
1Autodesk 1Fbx Software Development Kit Nov 21, 2024 Apr 17, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it. |
5Canonical FedoraprojectOpensuse+2 more5Fedora LeapUbuntu Linux+2 moreNov 21, 2024 Apr 17, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and app...Show more |
1Qualcomm 54Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+51 moreNov 21, 2024 Apr 16, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Possible use after free issue in pcm volume controls due to race condition exist in private data used in mixer controls in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdrag...Show more |
1Qualcomm 11Nicobar Firmware Qcs405 FirmwareRennell Firmware+8 moreNov 21, 2024 Apr 16, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Use after free issue when MAP and UNMAP calls at same time as data structure used my MAP may be freed by UNMAP function in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voi...Show more |