CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,549 vulnerabilities with CWE-416
CVE-2023-29325 HIGH
Microsoft Windows OLE - Remote Code Execution
CVSS 8.1
CVE-2023-24953 HIGH
Microsoft Excel - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2023-24947 HIGH
Microsoft Windows Bluetooth Driver - Remote Code Execution
CVSS 8.8
CVE-2023-31974 MEDIUM
yasm v1.3.0 - Use-After-Free in Error Function
CVSS 5.5
CVE-2023-31972 MEDIUM
yasm v1.3.0 - Use-After-Free in pp_getline
CVSS 5.5
CVE-2023-2513 MEDIUM
Linux Kernel < 5.19 - Use-After-Free in ext4 Extended Attribute Handling
CVSS 6.7
CVE-2023-32233 HIGH
Linux Kernel 3.13-6.3.1 - Use-After-Free in Netfilter nf_tables via Anonymous Set Mishandling
CVSS 7.8
CVE-2023-27969 HIGH
iPadOS < 15.7.4 - Use-After-Free
CVSS 7.8
CVE-2023-32269 MEDIUM
Linux Kernel < 6.1.11 - Use-After-Free in AF_NETROM Socket Accept
CVSS 6.7
CVE-2023-2461 HIGH
Google Chrome < 113.0.5672.63 - Use-After-Free in OS Inputs
CVSS 8.8
CVE-2023-2236 HIGH
Linux Kernel 5.19-6.0.11 - Use-After-Free in io_uring Subsystem
CVSS 7.8
CVE-2023-2235 HIGH
Linux Kernel 5.13-5.15.104 - Use-After-Free in Performance Events System
CVSS 7.8
CVE-2023-30549 HIGH
Apptainer < 1.1.8 - Use-After-Free via ext4 Filesystem Mounting
CVSS 7.1
CVE-2023-27352 HIGH
Sonos One Firmware 70.3-35220 - Unauthenticated Remote Code Execution via SMB Directory Query
CVSS 8.8
CVE-2023-2162 MEDIUM
Linux Kernel < 6.2 - Use-After-Free in iscsi_sw_tcp_session_create
CVSS 5.5
CVE-2023-21096 CRITICAL
Android - Use-After-Free in OnWakelockReleased
CVSS 9.8
CVE-2023-30612 MEDIUM
Cloud Hypervisor v30.0-31.0 - Denial of Service via HTTP API Socket File Descriptor Manipulation
CVSS 4.0
CVE-2023-2135 HIGH
Google Chrome <112.0.5615.137 - Use After Free
CVSS 7.5
CVE-2023-28984 MEDIUM
Juniper Networks Junos OS - QFX Series - Use After Free
CVSS 5.3
CVE-2023-28980 MEDIUM
Juniper Networks Junos OS - Use After Free
CVSS 5.5
CVE-2023-30772 MEDIUM
Linux Kernel < 6.2.9 - Use-After-Free in DA9150 Charger Driver
CVSS 6.4
CVE-2023-29132 MEDIUM
irssi 1.3.0-1.4.3 - Use-After-Free in Special Collector Reference
CVSS 5.3
CVE-2023-26414 HIGH
Adobe Substance 3D Designer <12.4.0 - Use After Free
CVSS 7.8
CVE-2023-26410 HIGH
Adobe Substance 3D Designer <12.4.0 - Use After Free
CVSS 7.8
CVE-2023-26392 HIGH
Adobe Substance 3D Stager <2.0.1 - Use After Free
CVSS 7.8
Details
Vulnerabilities 7,549
Exploit Likelihood High