CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,545 vulnerabilities with CWE-416
CVE-2024-38066 HIGH
Windows Win32k - Privilege Escalation
CVSS 7.8
CVE-2024-38059 HIGH
Windows 10/11, Server 2022 Elevation of Privilege via Win32k Use-After-Free
CVSS 7.8
CVE-2024-38053 HIGH
Windows Layer-2 Bridge Network Driver - Remote Code Execution
CVSS 8.8
CVE-2024-37320 HIGH
SQL Server 2016/2017/2019/2022 Remote Code Execution via Use-After-Free
CVSS 8.8
CVE-2024-35264 HIGH
.NET 8.0.0-8.0.6 - Remote Code Execution via Use-After-Free
CVSS 8.1
CVE-2024-21332 HIGH
SQL Server 2016-2022 Remote Code Execution via Use-After-Free in Native Client OLE DB Provider
CVSS 8.8
CVE-2024-21308 HIGH
Microsoft SQL Server 2016-2022 Remote Code Execution via OLE DB Provider Use-After-Free
CVSS 8.8
CVE-2024-21303 HIGH
Microsoft SQL Server 2016-2022 Remote Code Execution via OLE DB Provider
CVSS 8.8
CVE-2024-39486 HIGH
Linux Kernel - Use-After-Free in drm_file_update_pid
CVSS 7.0
CVE-2024-37030 HIGH
OpenHarmony < 4.0 - Remote Code Execution via Use-After-Free
CVSS 8.2
CVE-2024-39305 MEDIUM
Envoy < 1.30.4, 1.29.7, 1.28.5, 1.27.7 - Use-After-Free in Route Hash Policy Cookie Attributes
CVSS 6.5
CVE-2024-23380 HIGH
Qualcomm FastConnect and Flight RB5 5G Platform Firmware - Use-After-Free in VBO Bind Operation
CVSS 8.4
CVE-2024-23373 HIGH
Qualcomm QCA6436 Firmware - Use-After-Free in IOMMU Unmap Operation
CVSS 8.4
CVE-2024-38375 MEDIUM
@fastly/js-compute <3.16.0 - Use After Free
CVSS 5.3
CVE-2024-39463 HIGH
Linux Kernel 5.11-5.15.167, 5.16-6.1.93, 6.2-6.6.33, 6.7-6.9.4 - Use-After-Free in 9p Dentry FID List
CVSS 7.8
CVE-2024-38385 MEDIUM
Linux Kernel 6.5-6.6.33, 6.7-6.9.4, 6.10 - Use-After-Free in irq_find_at_or_after()
CVSS 5.5
CVE-2024-37007 HIGH
AutoCAD 2022-2022.1.5 - Use-After-Free in pskernel.DLL via X_B and X_T File Parsing
CVSS 7.8
CVE-2024-37004 HIGH
Autodesk AutoCAD 2022-2022.1.5 - Use-After-Free in ASMKERN229A.dll via SLDPRT File Parsing
CVSS 7.8
CVE-2024-23158 HIGH
Autodesk AutoCAD and Related Products 2022-<2022.1.5 - Use-After-Free via IGES File Parsing
CVSS 7.8
CVE-2024-23142 HIGH
Autodesk AutoCAD 2022-<2022.1.5 - Use-After-Free via Malicious CATPART/STP/MODEL File Parsing
CVSS 7.8
CVE-2024-6293 HIGH
Google Chrome <126.0.6478.126 - Use After Free
CVSS 8.8
CVE-2024-6292 HIGH
Google Chrome <126.0.6478.126 - Use After Free
CVSS 8.8
CVE-2024-6291 HIGH
Google Chrome <126.0.6478.126 - Use After Free
CVSS 8.8
CVE-2024-6290 HIGH
Google Chrome <126.0.6478.126 - Use After Free
CVSS 8.8
CVE-2024-38630 HIGH
Linux Kernel - Use-After-Free in cpu5wdt_trigger Timer Handler
CVSS 7.8
Details
Vulnerabilities 7,545
Exploit Likelihood High