CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,566 vulnerabilities with CWE-416
CVE-2022-37379 MEDIUM
Foxit PDF Reader 11.2.1.53537 - Use-After-Free in AFSpecial_KeystrokeEx
CVSS 5.5
CVE-2022-37378 HIGH
Foxit PDF Editor 11.1.1.53537 - Remote Code Execution via JavaScript Function Optimization
CVSS 7.8
CVE-2022-37374 HIGH
PDF-XChange Editor - Use-After-Free in PNG File Parser
CVSS 7.8
CVE-2022-37359 HIGH
PDF-XChange Editor - Use-After-Free in J2K File Parsing
CVSS 7.8
CVE-2022-28641 HIGH
Bentley MicroStation CONNECT 10.16.02.34 - RCE
CVSS 7.8
CVE-2022-28310 HIGH
Bentley MicroStation and View < 10.16.03 - Remote Code Execution via SKP File Parsing
CVSS 7.8
CVE-2022-28303 HIGH
Bentley Microstation and View < 10.16.03 - Remote Code Execution via SKP File Parsing
CVSS 7.8
CVE-2022-48434 HIGH
FFmpeg < 5.1.2 - Use-After-Free in libavcodec/pthread_frame.c
CVSS 8.1
CVE-2022-4095 HIGH
Linux kernel <5.19.2 - Use After Free
CVSS 7.8
CVE-2022-42332 HIGH
Xen >= 3.2.0 - Use-After-Free in Shadow Mode Log-Dirty Tracking
CVSS 7.8
CVE-2022-47460 MEDIUM
Android - Use-After-Free in GPU Device
CVSS 5.5
CVE-2022-33245 MEDIUM
Qualcomm WLAN Firmware - Memory Corruption due to Use After Free
CVSS 6.7
CVE-2022-46394 HIGH
Arm Mali GPU Kernel Driver <r42p0 - Memory Corruption
CVSS 8.8
CVE-2022-3424 HIGH
Linux Kernel 2.6.33-4.9.337 - Use-After-Free in SGI GRU Driver
CVSS 7.8
CVE-2022-46395 HIGH
Arm Mali GPU Kernel Driver - Memory Corruption
CVSS 8.8
CVE-2022-46712 HIGH
macOS < 13.0 - Use-After-Free
CVSS 7.8
CVE-2022-42826 HIGH
Safari < 16.1 - Use-After-Free
CVSS 8.8
CVE-2022-48340 HIGH
GlusterFS 11.0 - Use-After-Free in dht_setxattr_mds_cbk
CVSS 7.5
CVE-2022-30539 HIGH
Intel Xeon Gold Firmware - Use-After-Free
CVSS 7.5
CVE-2022-40016 HIGH
media-server < 2022-08-06 - Use-After-Free in librtmp
CVSS 7.5
CVE-2022-47371 MEDIUM
Android - Use-After-Free in Bluetooth Driver
CVSS 5.5
CVE-2022-33225 MEDIUM
Trusted Application Environment - Use After Free
CVSS 6.7
CVE-2022-43552 MEDIUM
curl < 7.87.0 - Use-After-Free in HTTP Proxy Tunnel Shutdown
CVSS 5.9
CVE-2022-3094 HIGH
BIND 9.16.0-9.16.36 9.18.0-9.18.10 9.19.0-9.19.8 9.16.8-S1-9.16.36-S1 - Denial of Service via Dynamic DNS Update Flood
CVSS 7.5
CVE-2022-42414 MEDIUM
PDF-XChange Editor < 9.5.366.0 - Use-After-Free in PDF File Parser
CVSS 5.5
Details
Vulnerabilities 7,566
Exploit Likelihood High