CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,549 vulnerabilities with CWE-416
CVE-2023-26384 HIGH
Adobe Substance 3D Stager <2.0.1 - Use After Free
CVSS 7.8
CVE-2023-22235 HIGH
InCopy <18.1, 17.4 - Use After Free
CVSS 7.8
CVE-2023-26424 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26423 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26422 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26420 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26419 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26418 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26417 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-1990 MEDIUM
Linux Kernel < 6.3 - Use-After-Free in NFC NCI Ndlc Remove
CVSS 4.7
CVE-2023-1872 HIGH
Linux Kernel 5.7-5.16 - Use-After-Free in io_uring Fixed File Handling
CVSS 7.8
CVE-2023-1829 HIGH
Linux Kernel - Privilege Escalation
CVSS 7.8
CVE-2023-28308 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Race Condition
CVSS 6.6
CVE-2023-28307 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Race Condition
CVSS 6.6
CVE-2023-28306 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Race Condition
CVSS 6.6
CVE-2023-28305 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Race Condition
CVSS 6.6
CVE-2023-28297 HIGH
Windows 10/11, Server 2012/2016/2019/2022 - Elevation of Privilege via RPCSS Use-After-Free
CVSS 8.8
CVE-2023-28285 HIGH
Microsoft 365 Apps - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2023-28223 MEDIUM
Windows Server 2008, 2012, 2016, 2019 - Remote Code Execution via DNS Use-After-Free
CVSS 6.6
CVE-2023-24925 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - RCE
CVSS 8.8
CVE-2023-24914 HIGH
Windows 11 22H2 < 10.0.22621.1555 - Use-After-Free Elevation of Privilege
CVSS 7.0
CVE-2023-1989 HIGH
Linux Kernel 2.6.24-4.14.312 - Use-After-Free in btsdio_remove
CVSS 7.0
CVE-2023-26495 HIGH
Open Design Alliance Drawings SDK <2024.1 - Use After Free
CVSS 7.8
CVE-2023-28205 HIGH KEV
Safari < 16.4.1 - Use-After-Free via Maliciously Crafted Web Content
CVSS 8.8
CVE-2023-20664 MEDIUM
Android - Use-After-Free in gz
CVSS 6.7
Details
Vulnerabilities 7,549
Exploit Likelihood High