CWE-416— Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.— MITRE CWE catalog
8,288 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-416page 10 of 166
- CVE-2016-7892CRITICALCVSS 8.8EG 9.8⚠ KEV2016-12-15
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
- CVE-2016-7906MEDIUMCVSS 5.5EG 5.52017-01-18
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.
- CVE-2016-7910HIGHCVSS 7.8EG 7.82016-11-16
Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel before 4.7.1 allows local users to gain privileges by leveraging the execution of a certain stop operation even if the corresponding start ope…
- CVE-2016-7911HIGHCVSS 7.8EG 7.82016-11-16
Race condition in the get_task_ioprio function in block/ioprio.c in the Linux kernel before 4.6.6 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted ioprio_get system call.
- CVE-2016-7912HIGHCVSS 7.8EG 7.82016-11-16
Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux kernel before 4.5.3 allows local users to gain privileges by accessing an I/O data structure after a certain callback call.
- CVE-2016-7913HIGHCVSS 7.8EG 7.82016-11-16
The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name fr…
- CVE-2016-7978CRITICALCVSS 9.8EG 9.82017-05-23
Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.
- CVE-2016-8618CRITICALCVSS 5.3EG 9.82018-07-31
The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables.
- CVE-2016-8619CRITICALCVSS 5.3EG 9.82018-08-01
The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
- CVE-2016-8623HIGHCVSS 3.3EG 7.52018-08-01
A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-after-free leading to information disclosure.
- CVE-2016-8655HIGHCVSS 7.8EG 7.82016-12-08
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to…
- CVE-2016-8674MEDIUMCVSS 5.5EG 5.52017-02-15
The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.
- CVE-2016-9067MEDIUMCVSS 6.5EG 6.52018-06-11
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
- CVE-2016-9068HIGHCVSS 7.5EG 7.52018-06-11
A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.
- CVE-2016-9069HIGHCVSS 7.8EG 7.82018-10-18
A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
- CVE-2016-9079CRITICALCVSS 7.5EG 9.0⚠ KEV2018-06-11
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Fi…
- CVE-2016-9120HIGHCVSS 7.8EG 7.82016-12-08
Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) by calling ION_IOC_FREE on two CPUs at the sam…
- CVE-2016-9137CRITICALCVSS 9.8EG 9.82017-01-04
Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted seria…
- CVE-2016-9138CRITICALCVSS 9.8EG 9.82017-01-04
PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as dem…
- CVE-2016-9279HIGHCVSS 7.5EG 7.52017-01-18
Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853.
- CVE-2016-9373MEDIUMCVSS 5.9EG 5.92016-11-17
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dcerpc-nt.c and epan/dissectors/packet-dce…
- CVE-2016-9401MEDIUMCVSS 5.5EG 5.52017-01-23
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
- CVE-2016-9576HIGHCVSS 7.8EG 7.82016-12-28
The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of serv…
- CVE-2016-9584CRITICALCVSS 9.1EG 9.12017-01-18
libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file.
- CVE-2016-9591MEDIUMCVSS 5.5EG 5.52018-03-09
JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.
- CVE-2016-9678CRITICALCVSS 9.8EG 9.82017-01-18
Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
- CVE-2016-9794HIGHCVSS 7.8EG 7.82016-12-28
Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact v…
- CVE-2016-9798MEDIUMCVSS 5.3EG 5.32016-12-03
In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
- CVE-2016-9896HIGHCVSS 8.1EG 8.12018-06-11
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.
- CVE-2016-9898CRITICALCVSS 9.8EG 9.82018-06-11
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
- CVE-2016-9899CRITICALCVSS 9.8EG 9.82018-06-11
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
- CVE-2016-9923MEDIUMCVSS 5.5EG 5.52016-12-23
Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging the device in the guest. A guest user/process could use this flaw to crash a Qemu process o…
- CVE-2016-9936CRITICALCVSS 9.8EG 9.82017-01-04
The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerab…
- CVE-2017-0070HIGHCVSS 7.5EG 8.82017-03-17
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could exec…
- CVE-2017-0261CRITICALCVSS 7.8EG 9.0⚠ KEV2017-05-12
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique f…
- CVE-2017-0263CRITICALCVSS 7.8EG 9.0⚠ KEV2017-05-12
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain priv…
- CVE-2017-0428HIGHCVSS 7.8EG 7.82017-02-08
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2017-0727HIGHCVSS 7.8EG 7.82017-08-09
A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-33004354.
- CVE-2017-0861HIGHCVSS 7.8EG 7.82017-11-16
Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.
- CVE-2017-0869HIGHCVSS 7.8EG 7.82018-01-12
NVIDIA driver contains an integer overflow vulnerability which could cause a use after free and possibly lead to an elevation of privilege enabling code execution as a privileged process. This issue is rated as high. Version: N/A. Android …
- CVE-2017-1000172CRITICALCVSS 9.8EG 9.82017-11-17
Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sublexer' pointer has been freed. Line 542 of gravity_lexer.c. 'lexer' is being used to access a variable but 'lexer' has …
- CVE-2017-1000211MEDIUMCVSS 5.3EG 5.32017-11-17
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
- CVE-2017-1000421CRITICALCVSS 9.8EG 9.82018-01-02
Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution
- CVE-2017-10661HIGHCVSS 7.0EG 7.02017-08-19
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper mig…
- CVE-2017-10672CRITICALCVSS 9.8EG 9.82017-06-29
Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
- CVE-2017-10686HIGHCVSS 7.8EG 7.82017-06-29
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used a…
- CVE-2017-10788CRITICALCVSS 9.8EG 9.82017-07-01
The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL serve…
- CVE-2017-1081HIGHCVSS 7.5EG 7.52018-04-10
In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep frags" options can cause a kernel panic when fed specially crafted packet fragments due to incorrect memory handling.
- CVE-2017-10941HIGHCVSS 8.8EG 8.82017-10-31
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open…
- CVE-2017-10945HIGHCVSS 8.8EG 8.82017-10-31
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open…
Map vulnerabilities like CWE-416 to your infrastructure
EchelonGraph correlates every CVE — across CWE-416 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →