Перейти к содержимому
Noroxi

CWE-416 · 8 147 записей

Использование памяти после освобождения

Почему это происходит?

После освобождения области памяти продолжает использоваться другая ссылка на неё. К этому моменту та же область может быть выделена под другие данные.

Уязвимый и исправленный код

Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.

Уязвимый код

c
free(dev->buf);/* ... другой поток всё ещё работает ... */process(dev->buf);

Исправленный код

c
lock(&dev->lock);free(dev->buf);dev->buf = NULL;unlock(&dev->lock);

Как предотвратить

  1. 01Сразу обнуляйте (NULL) освобождённый указатель.
  2. 02Для общих объектов используйте подсчёт ссылок и блокировки.
  3. 03Тестируйте с детекторами ошибок памяти (санитайзерами).

CVE этого класса

8 211 записей

  • CVE-2019-0708
    99Срочно

    A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · windows 716 мая 2019 г.

  • CVE-2021-31166
    99Срочно

    HTTP Protocol Stack Remote Code Execution Vulnerability

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · windows 10 200411 мая 2021 г.

  • CVE-2015-5119
    99Срочно

    Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    adobe · flash player8 июл. 2015 г.

  • CVE-2015-0313
    98Срочно

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %

    adobe · flash player2 февр. 2015 г.

  • CVE-2015-5122
    97Срочно

    Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %

    adobe · flash player14 июл. 2015 г.

  • CVE-2020-3992
    94Срочно

    OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %

    vmware · cloud foundation20 окт. 2020 г.

  • CVE-2014-1776
    94Срочно

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %

    microsoft · internet explorer27 апр. 2014 г.

  • CVE-2010-0249
    93Срочно

    Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 92 %

    microsoft · internet explorer15 янв. 2010 г.

  • CVE-2010-3962
    91Срочно

    Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors relate

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 97 %

    microsoft · internet explorer5 нояб. 2010 г.

  • CVE-2013-3893
    91Срочно

    Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote a

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 88 %

    microsoft · internet explorer18 сент. 2013 г.

  • CVE-2014-0322
    91Срочно

    Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 85 %

    microsoft · internet explorer14 февр. 2014 г.

  • CVE-2021-26411
    89Срочно

    Internet Explorer Memory Corruption Vulnerability

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 81 %

    microsoft · edge11 мар. 2021 г.

  • CVE-2012-4792
    89Срочно

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 79 %

    microsoft · internet explorer30 дек. 2012 г.

  • CVE-2018-15982
    88Срочно

    Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 90 %

    adobe · flash player18 янв. 2019 г.

  • CVE-2018-4878
    88Срочно

    A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 90 %

    adobe · flash player6 февр. 2018 г.

  • CVE-2013-1347
    88Срочно

    Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessi

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 78 %

    microsoft · internet explorer5 мая 2013 г.

  • CVE-2013-3897
    88Срочно

    Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 77 %

    microsoft · internet explorer9 окт. 2013 г.

  • CVE-2013-2551
    87Срочно

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 74 %

    microsoft · internet explorer11 мар. 2013 г.

  • CVE-2016-9079
    86Срочно

    A use-after-free vulnerability in SVG Animation has been discovered.

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 87 %

    debian · debian linux11 июн. 2018 г.

  • CVE-2020-0674
    86Срочно

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 87 %

    microsoft · internet explorer11 февр. 2020 г.

  • CVE-2009-4324
    86Срочно

    Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 82 %

    adobe · acrobat14 дек. 2009 г.

  • CVE-2012-4969
    86Срочно

    Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attacker

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 80 %

    microsoft · internet explorer18 сент. 2012 г.

  • CVE-2017-0261
    84Срочно

    Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 78 %

    microsoft · office12 мая 2017 г.

  • CVE-2019-1429
    83Срочно

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 77 %

    microsoft · internet explorer12 нояб. 2019 г.

  • CVE-2021-40449
    83Срочно

    Win32k Elevation of Privilege Vulnerability

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 74 %

    microsoft · windows 10 150712 окт. 2021 г.

Все классы уязвимостей