CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,548 vulnerabilities with CWE-416
CVE-2023-35351 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution in Active Directory Certificate Services
CVSS 6.6
CVE-2023-35323 HIGH
Windows 11 21H2 < 10.0.22000.2176 and Windows Server 2022 - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2023-35313 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution via OCSP SnapIn Use-After-Free
CVSS 7.8
CVE-2023-35300 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution via RPC Runtime Use-After-Free
CVSS 8.8
CVE-2023-33153 MEDIUM
Microsoft 365 Apps and Office - Remote Code Execution via Use-After-Free
CVSS 6.8
CVE-2023-33149 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2023-32055 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Active Template Library Use-After-Free Elevation of Privilege
CVSS 6.7
CVE-2023-32038 HIGH
Microsoft ODBC Driver - Remote Code Execution via Use-After-Free
CVSS 8.8
CVE-2023-32033 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via Failover Cluster Use-After-Free
CVSS 6.6
CVE-2023-21756 HIGH
Windows Win32k - Privilege Escalation
CVSS 7.8
CVE-2023-3269 HIGH
Linux Kernel >=6.1 <6.1.37 - Use-After-Free in VMA Lock Handling
CVSS 7.8
CVE-2023-1902 MEDIUM
Zephyr < 3.3.0 - Use-After-Free in Bluetooth HCI Host Layer
CVSS 5.9
CVE-2023-29824 CRITICAL
scipy < 1.8.0 - Use-After-Free in Py_FindObjects()
CVSS 9.8
CVE-2023-37454 MEDIUM
Linux Kernel < 6.4.2 - Use-After-Free in UDF Filesystem Superblock Handling
CVSS 5.5
CVE-2023-31248 HIGH
Linux Kernel >=5.9 <5.10.188 - Use-After-Free in nft_chain_lookup_byid
CVSS 7.8
CVE-2023-37209 HIGH
Firefox < 115.0 - Use-After-Free in NotifyOnHistoryReload
CVSS 8.8
CVE-2023-37202 HIGH
Firefox < 115.0 and Firefox ESR < 102.13 - Use-After-Free via Cross-Compartment Wrapper
CVSS 8.8
CVE-2023-37201 HIGH
Firefox < 115.0 and Firefox ESR < 102.13 - Use-After-Free via WebRTC Connection
CVSS 8.8
CVE-2023-21672 HIGH
Audio <version> - Memory Corruption
CVSS 8.4
CVE-2023-3439 MEDIUM
Linux Kernel 5.15-5.17 - Use-After-Free in MCTP Protocol
CVSS 4.7
CVE-2023-3390 HIGH
Linux Kernel 3.16-4.14.321 - Use-After-Free in netfilter nf_tables_api.c
CVSS 7.8
CVE-2023-3389 HIGH
Linux Kernel 5.10.162-5.10.184 - Use-After-Free in io_uring Subsystem
CVSS 7.8
CVE-2023-21147 HIGH
Android - Use-After-Free in lwis_i2c_device_disable
CVSS 7.8
CVE-2023-21146 MEDIUM
Android - Use-After-Free in Kernel
CVSS 6.7
CVE-2023-25002 HIGH
Autodesk 3ds Max, Navisworks, Revit, and VRED - Use-After-Free via Malicious SKP File
CVSS 7.8
Details
Vulnerabilities 7,548
Exploit Likelihood High