CWE-416 · 8 147 записей
Использование памяти после освобождения
Почему это происходит?
После освобождения области памяти продолжает использоваться другая ссылка на неё. К этому моменту та же область может быть выделена под другие данные.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
free(dev->buf);/* ... другой поток всё ещё работает ... */process(dev->buf);Исправленный код
lock(&dev->lock);free(dev->buf);dev->buf = NULL;unlock(&dev->lock);Как предотвратить
- 01Сразу обнуляйте (NULL) освобождённый указатель.
- 02Для общих объектов используйте подсчёт ссылок и блокировки.
- 03Тестируйте с детекторами ошибок памяти (санитайзерами).
CVE этого класса
8 211 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2019-0708Готовый эксплойт | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attackermicrosoft · windows 7 · CWE-416 | Критическая9,8 | KEV | 100,0 % | 16 мая 2019 г. |
99Срочно | CVE-2021-31166Готовый эксплойт | HTTP Protocol Stack Remote Code Execution Vulnerabilitymicrosoft · windows 10 2004 · CWE-416 | Критическая9,8 | KEV | 99,9 % | 11 мая 2021 г. |
99Срочно | CVE-2015-5119Готовый эксплойт | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Критическая9,8 | KEV | 99,3 % | 8 июл. 2015 г. |
98Срочно | CVE-2015-0313Готовый эксплойт | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Критическая9,8 | KEV | 95,3 % | 2 февр. 2015 г. |
97Срочно | CVE-2015-5122Готовый эксплойт | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Критическая9,8 | KEV | 94,0 % | 14 июл. 2015 г. |
94Срочно | CVE-2020-3992Готовый эксплойт | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a vmware · cloud foundation · CWE-416 | Критическая9,8 | KEV | 83,0 % | 20 окт. 2020 г. |
94Срочно | CVE-2014-1776Готовый эксплойт | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denialmicrosoft · internet explorer · CWE-416 | Критическая9,8 | KEV | 82,7 % | 27 апр. 2014 г. |
93Срочно | CVE-2010-0249Готовый эксплойт | Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2microsoft · internet explorer · CWE-416 | Высокая8,8 | KEV | 91,9 % | 15 янв. 2010 г. |
91Срочно | CVE-2010-3962Готовый эксплойт | Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors relatemicrosoft · internet explorer · CWE-416 | Высокая8,1 | KEV | 96,8 % | 5 нояб. 2010 г. |
91Срочно | CVE-2013-3893Готовый эксплойт | Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote amicrosoft · internet explorer · CWE-416 | Высокая8,8 | KEV | 87,5 % | 18 сент. 2013 г. |
91Срочно | CVE-2014-0322Готовый эксплойт | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involvingmicrosoft · internet explorer · CWE-416 | Высокая8,8 | KEV | 85,1 % | 14 февр. 2014 г. |
89Срочно | CVE-2021-26411Готовый эксплойт | Internet Explorer Memory Corruption Vulnerabilitymicrosoft · edge · CWE-416 | Высокая8,8 | KEV | 80,8 % | 11 мар. 2021 г. |
89Срочно | CVE-2012-4792Готовый эксплойт | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web microsoft · internet explorer · CWE-416 | Высокая8,8 | KEV | 78,8 % | 30 дек. 2012 г. |
88Срочно | CVE-2018-15982Готовый эксплойт | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.adobe · flash player · CWE-416 | Высокая7,8 | KEV | 89,6 % | 18 янв. 2019 г. |
88Срочно | CVE-2018-4878Готовый эксплойт | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.adobe · flash player · CWE-416 | Высокая7,8 | KEV | 89,5 % | 6 февр. 2018 г. |
88Срочно | CVE-2013-1347Готовый эксплойт | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessimicrosoft · internet explorer · CWE-416 | Высокая8,8 | KEV | 77,7 % | 5 мая 2013 г. |
88Срочно | CVE-2013-3897Готовый эксплойт | Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers microsoft · internet explorer · CWE-416 | Высокая8,8 | KEV | 77,3 % | 9 окт. 2013 г. |
87Срочно | CVE-2013-2551Готовый эксплойт | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted webmicrosoft · internet explorer · CWE-416 | Высокая8,8 | KEV | 74,1 % | 11 мар. 2013 г. |
86Срочно | CVE-2016-9079Готовый эксплойт | A use-after-free vulnerability in SVG Animation has been discovered.debian · debian linux · CWE-416 | Высокая7,5 | KEV | 87,4 % | 11 июн. 2018 г. |
86Срочно | CVE-2020-0674Готовый эксплойт | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripmicrosoft · internet explorer · CWE-416 | Высокая7,5 | KEV | 86,9 % | 11 февр. 2020 г. |
86Срочно | CVE-2009-4324Готовый эксплойт | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before adobe · acrobat · CWE-416 | Высокая7,8 | KEV | 81,9 % | 14 дек. 2009 г. |
86Срочно | CVE-2012-4969Готовый эксплойт | Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackermicrosoft · internet explorer · CWE-416 | Высокая8,1 | KEV | 80,3 % | 18 сент. 2012 г. |
84Срочно | CVE-2017-0261Готовый эксплойт | Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly microsoft · office · CWE-416 | Высокая7,8 | KEV | 78,1 % | 12 мая 2017 г. |
83Срочно | CVE-2019-1429Готовый эксплойт | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripmicrosoft · internet explorer · CWE-416 | Высокая7,5 | KEV | 77,3 % | 12 нояб. 2019 г. |
83Срочно | CVE-2021-40449Готовый эксплойт | Win32k Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-416 | Высокая7,8 | KEV | 74,1 % | 12 окт. 2021 г. |
- CVE-2019-070899Срочно
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 716 мая 2019 г.
- CVE-2021-3116699Срочно
HTTP Protocol Stack Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 10 200411 мая 2021 г.
- CVE-2015-511999Срочно
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · flash player8 июл. 2015 г.
- CVE-2015-031398Срочно
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %adobe · flash player2 февр. 2015 г.
- CVE-2015-512297Срочно
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player14 июл. 2015 г.
- CVE-2020-399294Срочно
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %vmware · cloud foundation20 окт. 2020 г.
- CVE-2014-177694Срочно
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %microsoft · internet explorer27 апр. 2014 г.
- CVE-2010-024993Срочно
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 92 %microsoft · internet explorer15 янв. 2010 г.
- CVE-2010-396291Срочно
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors relate
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 97 %microsoft · internet explorer5 нояб. 2010 г.
- CVE-2013-389391Срочно
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote a
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 88 %microsoft · internet explorer18 сент. 2013 г.
- CVE-2014-032291Срочно
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 85 %microsoft · internet explorer14 февр. 2014 г.
- CVE-2021-2641189Срочно
Internet Explorer Memory Corruption Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 81 %microsoft · edge11 мар. 2021 г.
- CVE-2012-479289Срочно
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 79 %microsoft · internet explorer30 дек. 2012 г.
- CVE-2018-1598288Срочно
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 90 %adobe · flash player18 янв. 2019 г.
- CVE-2018-487888Срочно
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 90 %adobe · flash player6 февр. 2018 г.
- CVE-2013-134788Срочно
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessi
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 78 %microsoft · internet explorer5 мая 2013 г.
- CVE-2013-389788Срочно
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 77 %microsoft · internet explorer9 окт. 2013 г.
- CVE-2013-255187Срочно
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 74 %microsoft · internet explorer11 мар. 2013 г.
- CVE-2016-907986Срочно
A use-after-free vulnerability in SVG Animation has been discovered.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 87 %debian · debian linux11 июн. 2018 г.
- CVE-2020-067486Срочно
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 87 %microsoft · internet explorer11 февр. 2020 г.
- CVE-2009-432486Срочно
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 82 %adobe · acrobat14 дек. 2009 г.
- CVE-2012-496986Срочно
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attacker
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 80 %microsoft · internet explorer18 сент. 2012 г.
- CVE-2017-026184Срочно
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 78 %microsoft · office12 мая 2017 г.
- CVE-2019-142983Срочно
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 77 %microsoft · internet explorer12 нояб. 2019 г.
- CVE-2021-4044983Срочно
Win32k Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 74 %microsoft · windows 10 150712 окт. 2021 г.