The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
7,549 vulnerabilities with CWE-416
CVE-2023-26384
HIGH
Adobe Substance 3D Stager <2.0.1 - Use After Free
CVSS 7.8
CVE-2023-22235
HIGH
InCopy <18.1, 17.4 - Use After Free
CVSS 7.8
CVE-2023-26424
HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26423
HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26422
HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26420
HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26419
HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26418
HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-26417
HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - Use After Free
CVSS 7.8
CVE-2023-1990
MEDIUM
Linux Kernel < 6.3 - Use-After-Free in NFC NCI Ndlc Remove
CVSS 4.7
CVE-2023-1872
HIGH
Linux Kernel 5.7-5.16 - Use-After-Free in io_uring Fixed File Handling
CVSS 7.8
CVE-2023-1829
HIGH
Linux Kernel - Privilege Escalation
CVSS 7.8
CVE-2023-28308
MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Race Condition
CVSS 6.6
CVE-2023-28307
MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Race Condition
CVSS 6.6
CVE-2023-28306
MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Race Condition
CVSS 6.6
CVE-2023-28305
MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Race Condition
CVSS 6.6
CVE-2023-28297
HIGH
Windows 10/11, Server 2012/2016/2019/2022 - Elevation of Privilege via RPCSS Use-After-Free
CVSS 8.8
CVE-2023-28285
HIGH
Microsoft 365 Apps - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2023-28223
MEDIUM
Windows Server 2008, 2012, 2016, 2019 - Remote Code Execution via DNS Use-After-Free
CVSS 6.6
CVE-2023-24925
HIGH
Microsoft PostScript and PCL6 Class Printer Driver - RCE
CVSS 8.8
CVE-2023-24914
HIGH
Windows 11 22H2 < 10.0.22621.1555 - Use-After-Free Elevation of Privilege
CVSS 7.0
CVE-2023-1989
HIGH
Linux Kernel 2.6.24-4.14.312 - Use-After-Free in btsdio_remove
CVSS 7.0
CVE-2023-26495
HIGH
Open Design Alliance Drawings SDK <2024.1 - Use After Free
CVSS 7.8
CVE-2023-28205
HIGH
KEV
Safari < 16.4.1 - Use-After-Free via Maliciously Crafted Web Content
CVSS 8.8
CVE-2023-20664
MEDIUM
Android - Use-After-Free in gz
CVSS 6.7
Details
Vulnerabilities
7,549
Exploit Likelihood
High