← Back
CWE-416

7,425 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

JSON object

Loading...

CVEs (7,425)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Nov 21, 2024
Sep 6, 2019
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
In the Android kernel in the mnh driver there is a race condition due to insufficient locking. This could lead to a use-after-free which could lead to escalation of privilege with System execution privileges needed. User...Show more
In the Android kernel in the mnh driver there is a race condition due to insufficient locking. This could lead to a use-after-free which could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Show less
2Libslirp Project
Qemu
2Libslirp
Qemu
Nov 21, 2024
Sep 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
1Google
1Android
Nov 21, 2024
Sep 5, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no addi...Show more
In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
1Linux
1Linux Kernel
Nov 21, 2024
Sep 4, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in the Linux kernel before 4.16.7. A use-after-free can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c.
2Linux
Opensuse
2Leap
Linux Kernel
Nov 21, 2024
Sep 4, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in the Linux kernel before 5.0.10. SMB2_read in fs/cifs/smb2pdu.c has a use-after-free. NOTE: this was not fixed correctly in 5.0.10; see the 5.0.11 ChangeLog, which documents a memory leak.
2Linux
Opensuse
2Leap
Linux Kernel
Nov 21, 2024
Sep 4, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An issue was discovered in the Linux kernel before 5.0.10. SMB2_write in fs/cifs/smb2pdu.c has a use-after-free.
3Debian
LinuxOpensuse
3Debian Linux
LeapLinux Kernel
Nov 21, 2024
Sep 4, 2019
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() fails in hci_uart_set_proto() in drivers/bluetooth/hci_ldisc.c.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Nov 21, 2024
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Nov 21, 2024
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
2Debian
Videolan
2Debian Linux
Vlc Media Player
Nov 21, 2024
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
2Canonical
Irssi
2Irssi
Ubuntu Linux
Nov 21, 2024
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.
1Zephyrproject
1Zephyr
Nov 21, 2024
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all.
1Comodo
1Antivirus
Nov 21, 2024
Aug 28, 2019
N/A· v4
4.7 MEDIUM· v3
4.7 MEDIUM· v2
A use-after-free flaw in the sandbox container implemented in cmdguard.sys in Comodo Antivirus 12.0.0.6870 can be triggered due to a race condition when handling IRP_MJ_CLEANUP requests in the minifilter for directory ch...Show more
A use-after-free flaw in the sandbox container implemented in cmdguard.sys in Comodo Antivirus 12.0.0.6870 can be triggered due to a race condition when handling IRP_MJ_CLEANUP requests in the minifilter for directory change notifications. This allows an attacker to cause a denial of service (BSOD) when an executable is run inside the container.Show less
1Rust Openssl Project
1Rust Openssl
Nov 21, 2024
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
1Libflate Project
1Libflate
Nov 21, 2024
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution.
1Autodesk
1Design Review
Nov 21, 2024
Aug 23, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a use-after-free vulnerability, which may resul...Show more
Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a use-after-free vulnerability, which may result in code execution.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
Aug 21, 2019
N/A· v4
4.7 MEDIUM· v3
10.0 HIGH· v2
An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c.
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Nov 21, 2024
Aug 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use aft...Show more
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .Show less
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Nov 21, 2024
Aug 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use aft...Show more
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .Show less
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Nov 21, 2024
Aug 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use aft...Show more
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .Show less