CWE-416
7,425 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (7,425)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
VCFTools vcftools prior to version 0.1.15 is affected by: Use-after-free. The impact is: Denial of Service or possibly other impact (eg. code execution or information disclosure). The component is: The header::add_FILTER...Show more |
1Qualcomm 21Mdm9640 Firmware Qcs405 FirmwareQcs605 Firmware+18 moreNov 21, 2024 Jul 25, 2019 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 When computing the digest a local variable is used after going out of scope in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9640, QCS405, QCS605, SD 425, SD 427, SD 430, SD...Show more |
1Qualcomm 24Msm8909w Firmware Qcs405 FirmwareQcs605 Firmware+21 moreNov 21, 2024 Jul 25, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 Possible race condition that will cause a use-after-free when writing to two sysfs entries at nearly the same time in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon...Show more |
1Qualcomm 29Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+26 moreNov 21, 2024 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Protection is missing while accessing md sessions info via macro which can lead to use-after-free in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon...Show more |
1Qualcomm 21Msm8909w Firmware Qcs405 FirmwareQcs605 Firmware+18 moreNov 21, 2024 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Pointer dereference while freeing IFE resources due to lack of length check of in port resource. in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in...Show more |
1Qualcomm 28Mdm9206 Firmware Mdm9607 FirmwareMdm9640 Firmware+25 moreNov 21, 2024 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Multiple open and close from multiple threads will lead camera driver to access destroyed session data pointer in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon M...Show more |
1Qualcomm 33Ipq4019 Firmware Ipq8064 FirmwareMdm9206 Firmware+30 moreNov 21, 2024 Jul 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Access to freed memory can happen while reading from diag driver due to use after free issue in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon...Show more |
Jsish 2.4.70 2.047 is affected by: Use After Free. The impact is: denial of service and possibly arbitrary code execution. The component is: function Jsi_RegExpNew (jsi/jsiRegexp.c:39). The attack vector is: executing cr...Show more |
A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67. |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Jul 23, 2019 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a san...Show more |
1Mozilla 2Firefox ThunderbirdNov 25, 2025 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and...Show more |
1Mozilla 2Firefox ThunderbirdNov 25, 2025 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vu...Show more |
Jsish 2.4.77 2.0477 is affected by: Use After Free. The impact is: denial of service. The component is: function Jsi_ObjFree (jsiObj.c:230). The attack vector is: executing crafted javascript code. The fixed version is:...Show more |
1Qualcomm 26Mdm9607 Firmware Mdm9640 FirmwareMsm8909w Firmware+23 moreNov 21, 2024 Jul 22, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Null pointer dereference occurs for channel context while opening glink channel in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9607, MDM9640, MSM8909W...Show more |
1Qualcomm 39Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+36 moreNov 21, 2024 Jul 22, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon V...Show more |
1Schneider Electric 1Zelio Soft 2 Nov 21, 2024 Jul 15, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code execution when opening a specially crafted Zelio Soft 2 project file. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraOniguruma+2 moreNov 21, 2024 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression....Show more |
In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local code execution with no additional execution privileges needed. User interaction is not needed for ex...Show more |