CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,566 vulnerabilities with CWE-416
CVE-2022-42408 MEDIUM
PDF-XChange Editor < 9.5.366.0 - Use-After-Free in EMF File Parsing
CVSS 5.5
CVE-2022-42374 HIGH
PDF-XChange Editor < 9.5.366.0 - Remote Code Execution via U3D File Parsing
CVSS 7.8
CVE-2022-45748 HIGH
assimp 5.1.4 - Use-After-Free in ColladaParser::ExtractDataObjectFromChannel
CVSS 8.8
CVE-2022-41858 HIGH
Linux Kernel < 4.9.311 - NULL Pointer Dereference in SLIP Driver Detach
CVSS 7.1
CVE-2022-46891 HIGH
Arm Mali GPU Kernel Driver - Use After Free
CVSS 8.8
CVE-2022-3977 HIGH
Linux Kernel 5.18-5.19.16 - Use-After-Free in MCTP DROPTAG ioctl
CVSS 7.8
CVE-2022-4696 HIGH
Linux Kernel 5.10-5.12 - Use-After-Free via io_uring IORING_OP_SPLICE
CVSS 7.8
CVE-2022-4382 MEDIUM
Linux Kernel - Use-After-Free in GadgetFS Superblock Operations
CVSS 6.4
CVE-2022-4379 HIGH
Linux Kernel >=5.6 <5.10.177 - Use-After-Free in __nfs42_ssc_open
CVSS 7.5
CVE-2022-25722 MEDIUM
Qualcomm APQ8096AU and other Firmware - Use-After-Free in DSP Services
CVSS 6.0
CVE-2022-47093 HIGH
GPAC < 2.2.0 - Use-After-Free in m2tsdmx_declare_pid
CVSS 7.8
CVE-2022-3863 MEDIUM
Google Chrome <100.0.4896.75 - Use After Free
CVSS 6.1
CVE-2022-3842 HIGH
Google Chrome <105.0.5195.125 - Use After Free
CVSS 7.5
CVE-2022-2742 HIGH
Google Chrome < 104.0.5112.79 - Use-After-Free in Exosphere via Crafted UI Interactions
CVSS 8.8
CVE-2022-47946 MEDIUM
Linux Kernel 5.10.x < 5.10.155 - Use-After-Free in io_sqpoll_wait_sq
CVSS 5.5
CVE-2022-47939 CRITICAL
Linux Kernel 5.15-5.19 < 5.19.2 - Use-After-Free in ksmbd SMB2_TREE_DISCONNECT
CVSS 9.8
CVE-2022-46882 CRITICAL
Firefox < 107.0 and Firefox ESR < 102.6 - Use-After-Free in WebGL Extensions
CVSS 9.8
CVE-2022-46880 MEDIUM
Firefox < 105.0 and Firefox ESR < 102.6 - Use-After-Free via Tex Unit Handling
CVSS 6.5
CVE-2022-45409 HIGH
Firefox < 107.0 and Firefox ESR < 102.5 - Use-After-Free in Garbage Collector
CVSS 8.8
CVE-2022-45407 HIGH
Firefox < 107.0 - Use-After-Free via FontFace() on Background Worker
CVSS 7.5
CVE-2022-45406 CRITICAL
Firefox < 107.0 and Firefox ESR < 102.5 - Use-After-Free in JavaScript Global Realm
CVSS 9.8
CVE-2022-45405 MEDIUM
Firefox < 107.0 and Firefox ESR < 102.5 - Use-After-Free in nsIInputStream
CVSS 6.5
CVE-2022-40960 MEDIUM
Firefox ESR < 102.3 & Thunderbird < 102.3 & Firefox < 105 - Use Aft...
CVSS 6.5
CVE-2022-38476 HIGH
Firefox ESR < 102.2 - Use After Free
CVSS 7.5
CVE-2022-34484 HIGH
Firefox < 102.0 and Firefox ESR < 91.11 - Use-After-Free
CVSS 8.8
Details
Vulnerabilities 7,566
Exploit Likelihood High