CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,547 vulnerabilities with CWE-416
CVE-2024-31578 HIGH
FFmpeg < 7.0 - Use-After-Free via av_hwframe_ctx_init
CVSS 7.5
CVE-2024-26909 MEDIUM
Linux Kernel 6.3-6.6.22, 6.7.0-6.7.10, 6.8 - Use-After-Free in DRM Bridge Registration
CVSS 5.5
CVE-2024-26907 HIGH
Linux Kernel - Use-After-Free in RDMA/mlx5 Eth Segment Handling
CVSS 7.8
CVE-2024-26898 HIGH
Linux Kernel - Use-After-Free in ATA over Ethernet Driver via aoecmd_cfg_pkts
CVSS 7.8
CVE-2024-26895 HIGH
Linux Kernel - Use-After-Free in wilc1000 WiFi Driver Interface Cleanup
CVSS 7.8
CVE-2024-26892 HIGH
Linux kernel 6.2.15-6.2.99 - Use-After-Free in mt7921e WiFi IRQ Handler
CVSS 7.8
CVE-2024-26886 MEDIUM
Linux Kernel 5.10.206-5.11 - Use-After-Free in Bluetooth Socket Locking
CVSS 6.5
CVE-2024-26875 MEDIUM
Linux Kernel - Use-After-Free in pvrusb2-context.c
CVSS 6.4
CVE-2024-26872 HIGH
Linux Kernel - Use-After-Free in SRPT Device Event Handler
CVSS 7.0
CVE-2024-26866 MEDIUM
Linux Kernel 4.10-6.6.22, 6.7.0-6.7.10, 6.8.0-6.8.1 - Use-After-Free in SPI LPSPI Probe
CVSS 5.5
CVE-2024-26865 HIGH
Linux Kernel 4.3-6.1.82, 6.2-6.6.22, 6.7-6.7.10, 6.8-6.8.1 - Use-After-Free in RDS TCP reqsk_timer_handler
CVSS 7.8
CVE-2024-26856 HIGH
Linux Kernel 5.14-5.15.151, 5.16-6.1.81, 6.2-6.6.21, 6.7-6.7.9 - Use-After-Free in sparx5_del_mact_entry
CVSS 7.8
CVE-2024-26852 HIGH
Linux Kernel 4.11-6.7.10 Use-After-Free in ip6_route_mpath_notify
CVSS 7.8
CVE-2024-26838 MEDIUM
Linux Kernel 5.14-5.15.150, 5.16-6.1.80, 6.2-6.6.19, 6.7-6.7.7 - Use-After-Free in IRDMA Tasklet Handling
CVSS 5.5
CVE-2024-3837 HIGH
Chrome < 124.0.6367.60 - Use-After-Free in QUIC
CVSS 8.8
CVE-2024-3834 HIGH
Google Chrome < 124.0.6367.60 - Use-After-Free in Downloads via Crafted HTML Page
CVSS 8.8
CVE-2024-30378 MEDIUM
Juniper Junos < 20.4 - Use After Free
CVSS 5.5
CVE-2024-3861 MEDIUM
Firefox < 125 and ESR < 115.10 - Use-After-Free via AlignedBuffer Self-Assignment
CVSS 4.0
CVE-2024-3857 HIGH
Firefox < 125 and ESR < 115.10 - Use-After-Free in JIT Argument Handling
CVSS 7.8
CVE-2024-3856 HIGH
Firefox < 125.0 - Use-After-Free during WASM Array Creation
CVSS 8.8
CVE-2024-3853 HIGH
Firefox < 125.0 - Use-After-Free during JavaScript Realm Initialization
CVSS 7.5
CVE-2024-30386 MEDIUM
Junos OS and Junos OS Evolved - Unauthenticated Use-After-Free in Layer 2 Address Learning Daemon
CVSS 5.3
CVE-2024-3515 MEDIUM
Google Chrome <123.0.6312.122 - Use After Free
CVSS 6.5
CVE-2024-29043 HIGH
Microsoft ODBC Driver for SQL Server 17.0.1.1-17.10.6.1 - Remote Code Execution
CVSS 8.8
CVE-2024-26241 HIGH
Windows 10/11, Server 2008/2012/2016/2019 Elevation of Privilege via Win32k Use-After-Free
CVSS 7.8
Details
Vulnerabilities 7,547
Exploit Likelihood High