CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,537 vulnerabilities with CWE-416
CVE-2024-53206 HIGH
Linux Kernel - Use-After-Free in reqsk_timer_handler
CVSS 7.8
CVE-2024-53194 HIGH
Linux Kernel < 4.19.325, 4.20.0-6.12.2 - Use-After-Free in PCI Hotplug
CVSS 7.8
CVE-2024-53186 HIGH
Linux Kernel - Use-After-Free in ksmbd_conn_handler_loop via Race Condition
CVSS 7.0
CVE-2024-53185 MEDIUM
Linux Kernel 6.6.57-6.6.63, 6.7.0-6.11.10, 6.12.0-6.12.1 - NULL Pointer Dereference in SMB Client Crypto Key Setup
CVSS 5.5
CVE-2024-53182 HIGH
Linux Kernel 6.12-6.12.1 - Use-After-Free in BFQ Scheduler
CVSS 7.8
CVE-2024-53179 HIGH
Linux Kernel < 6.6.70, 6.7.0-6.12.2, >=6.13 - Use-After-Free in SMB Session Signing Key
CVSS 7.8
CVE-2024-53177 HIGH
Linux Kernel < 6.6.64, 6.7.0-6.12.2 - Use-After-Free in SMB Cached Directory Handling
CVSS 7.8
CVE-2024-53174 HIGH
Linux Kernel < 5.4.287 Use-After-Free in SUNRPC Cache Entry Handling
CVSS 7.8
CVE-2024-53173 HIGH
Linux Kernel - Use-After-Free in NFSv4.0 Asynchronous Open
CVSS 7.8
CVE-2024-53171 HIGH
Linux Kernel - Use-After-Free in UBIFS TNC Commit
CVSS 7.8
CVE-2024-53170 HIGH
Linux Kernel 5.19-6.11.10, 6.1.0-6.1.126, 6.2.0-6.6.73, 6.7.0-6.11.10, 6.12.0-6.12.1 - Use-After-Free in Block Layer
CVSS 7.8
CVE-2024-53168 HIGH
Linux Kernel - Use-After-Free in sunrpc TCP Socket Handling
CVSS 7.8
CVE-2024-53166 HIGH
Linux Kernel 5.17-6.6.63, 6.1.0-6.1.129, 6.2.0-6.6.63, 6.7.0-6.11.10, 6.12.0-6.12.1 - Use-After-Free in BFQ Scheduler
CVSS 7.8
CVE-2024-53165 HIGH
Linux Kernel - Use-After-Free in register_intc_controller Error Handling
CVSS 7.8
CVE-2024-12175 HIGH
Rockwell Automation Arena < 16.20.07 - Use-After-Free via Crafted DOE File
CVSS 7.8
CVE-2024-12694 HIGH
Google Chrome < 131.0.6778.204 - Use-After-Free in Compositing
CVSS 8.8
CVE-2024-47040 HIGH
Android - Use-After-Free
CVSS 7.8
CVE-2024-49576 HIGH
Foxit Reader 2024.3.0.26795 - Use After Free
CVSS 8.8
CVE-2024-47810 HIGH
Foxit Reader 2024.3.0.26795 - Use After Free
CVSS 8.8
CVE-2024-47892 HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 RTM1 - Use-After-Free via GPU System Calls
CVSS 7.8
CVE-2024-46971 HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 RTM1 and >=24.2 RTM2 - Use-After-Free via GPU System Calls
CVSS 7.8
CVE-2024-49142 HIGH
Microsoft Access - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2024-49132 HIGH
Windows Remote Desktop Services - Remote Code Execution via Race Condition
CVSS 8.1
CVE-2024-49128 HIGH
Windows Server RCE via Improperly Locked Memory
CVSS 8.1
CVE-2024-49127 HIGH
Windows LDAP - Remote Code Execution via Race Condition
CVSS 8.1
Details
Vulnerabilities 7,537
Exploit Likelihood High