CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,548 vulnerabilities with CWE-416
CVE-2023-25001 HIGH
Autodesk Navisworks 2022-2023 - Use-After-Free via Malicious SKP File
CVSS 7.8
CVE-2023-3422 HIGH
Google Chrome < 114.0.5735.198 - Use-After-Free in Guest View
CVSS 8.8
CVE-2023-3421 HIGH
Google Chrome < 114.0.5735.198 - Use-After-Free in Media via Crafted HTML Page
CVSS 8.8
CVE-2023-3317 HIGH
Linux Kernel >=6.2 <6.2.15 - Use-After-Free in mt7921_check_offload_capability
CVSS 7.1
CVE-2023-32412 CRITICAL
iPadOS < 15.7.6 - Use-After-Free
CVSS 9.8
CVE-2023-32398 HIGH
iPadOS < 15.7.6 - Use-After-Free
CVSS 7.8
CVE-2023-32387 CRITICAL
macOS 11.0.0-11.7.6 - Use-After-Free
CVSS 9.8
CVE-2023-32373 HIGH KEV
Safari < 16.5 - Use-After-Free via Maliciously Crafted Web Content
CVSS 8.8
CVE-2023-34241 MEDIUM
OpenPrinting CUPS 2.0.0-2.4.6 - Use-After-Free in cupsdAcceptClient via httpClose
CVSS 5.3
CVE-2023-20893 HIGH
VMware vCenter Server - Use-After-Free in DCERPC Protocol Implementation
CVSS 8.1
CVE-2023-1999 MEDIUM
libwebp 0.4.2-1.3.0 - Use-After-Free in ApplyFiltersAndEncode
CVSS 5.3
CVE-2023-25747 HIGH
Firefox for Android < 110.1.0 - Use-After-Free in AAudio Backend
CVSS 7.5
CVE-2023-35829 HIGH
Linux Kernel < 6.3.2 - Use-After-Free in rkvdec_remove
CVSS 7.0
CVE-2023-35828 HIGH
Linux Kernel < 6.3.2 - Use-After-Free in renesas_usb3_remove
CVSS 7.0
CVE-2023-35827 HIGH
Linux Kernel < 6.3.8 - Use-After-Free in ravb_remove
CVSS 7.0
CVE-2023-35826 HIGH
Linux Kernel < 6.3.2 - Use-After-Free in cedrus_remove
CVSS 7.0
CVE-2023-35824 HIGH
Linux Kernel < 6.3.2 - Use-After-Free in dm1105_remove
CVSS 7.0
CVE-2023-35823 HIGH
Linux Kernel < 6.3.2 - Use-After-Free in saa7134_finidev
CVSS 7.0
CVE-2023-28287 HIGH
Microsoft Publisher - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2023-35784 CRITICAL
LibreSSL < 3.6.3 and 3.7.x < 3.7.3 - Use-After-Free in SSL_clear
CVSS 9.8
CVE-2023-34475 MEDIUM
ImageMagick < 7.1.1-10 - Use-After-Free in ReplaceXmpValue Function
CVSS 5.5
CVE-2023-34795 HIGH
xlsxio 0.1.2-0.2.34 - Use-After-Free in xlsxioread_sheetlist_close()
CVSS 7.8
CVE-2023-29356 HIGH
Microsoft ODBC Driver for SQL Server - RCE
CVSS 7.8
CVE-2023-29321 HIGH
Adobe Animate <22.0.9, 23.0.1 - Use After Free
CVSS 7.8
CVE-2023-21120 HIGH
Android - Use-After-Free in cdm_engine.cpp
CVSS 7.8
Details
Vulnerabilities 7,548
Exploit Likelihood High