Skip to content
Noroxi

CWE-416 · 8,147 records

Use after free

Why does it happen?

After a memory region is freed, another reference pointing to it is still used. By then, the same region may have been allocated for different data.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

c
free(dev->buf);/* ... another thread is still running ... */process(dev->buf);

Fixed

c
lock(&dev->lock);free(dev->buf);dev->buf = NULL;unlock(&dev->lock);

How to prevent it

  1. 01Set the freed pointer to NULL immediately.
  2. 02Use reference counting and locks for shared objects.
  3. 03Test with memory error detectors (sanitizers).

CVEs in this class

8,211 records

  • A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    microsoft · windows 7May 16, 2019

  • HTTP Protocol Stack Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    microsoft · windows 10 2004May 11, 2021

  • Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    adobe · flash playerJul 8, 2015

  • Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    adobe · flash playerFeb 2, 2015

  • Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    adobe · flash playerJul 14, 2015

  • OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    vmware · cloud foundationOct 20, 2020

  • Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    microsoft · internet explorerApr 27, 2014

  • Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2

    HighCVSS 8.8KEVWeaponizedEPSS 92%

    microsoft · internet explorerJan 15, 2010

  • Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors relate

    HighCVSS 8.1KEVWeaponizedEPSS 97%

    microsoft · internet explorerNov 5, 2010

  • Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote a

    HighCVSS 8.8KEVWeaponizedEPSS 88%

    microsoft · internet explorerSep 18, 2013

  • Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving

    HighCVSS 8.8KEVWeaponizedEPSS 85%

    microsoft · internet explorerFeb 14, 2014

  • Internet Explorer Memory Corruption Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 81%

    microsoft · edgeMar 11, 2021

  • Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web

    HighCVSS 8.8KEVWeaponizedEPSS 79%

    microsoft · internet explorerDec 30, 2012

  • Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.

    HighCVSS 7.8KEVWeaponizedEPSS 90%

    adobe · flash playerJan 18, 2019

  • A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.

    HighCVSS 7.8KEVWeaponizedEPSS 90%

    adobe · flash playerFeb 6, 2018

  • Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessi

    HighCVSS 8.8KEVWeaponizedEPSS 78%

    microsoft · internet explorerMay 5, 2013

  • Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers

    HighCVSS 8.8KEVWeaponizedEPSS 77%

    microsoft · internet explorerOct 9, 2013

  • Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web

    HighCVSS 8.8KEVWeaponizedEPSS 74%

    microsoft · internet explorerMar 11, 2013

  • A use-after-free vulnerability in SVG Animation has been discovered.

    HighCVSS 7.5KEVWeaponizedEPSS 87%

    debian · debian linuxJun 11, 2018

  • A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip

    HighCVSS 7.5KEVWeaponizedEPSS 87%

    microsoft · internet explorerFeb 11, 2020

  • Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before

    HighCVSS 7.8KEVWeaponizedEPSS 82%

    adobe · acrobatDec 14, 2009

  • Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attacker

    HighCVSS 8.1KEVWeaponizedEPSS 80%

    microsoft · internet explorerSep 18, 2012

  • Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly

    HighCVSS 7.8KEVWeaponizedEPSS 78%

    microsoft · officeMay 12, 2017

  • A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip

    HighCVSS 7.5KEVWeaponizedEPSS 77%

    microsoft · internet explorerNov 12, 2019

  • Win32k Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 74%

    microsoft · windows 10 1507Oct 12, 2021

All vulnerability classes