VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2024-57979High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: pps: Fix a use-after-free On a board running ntpd and gpsd, I'm seeing a consistent use-after-free in sys_exit() from gpsd when rebooting: pps pps1: removed -…

In the Linux kernel, the following vulnerability has been resolved: pps: Fix a use-after-free On a board running ntpd and gpsd, I'm seeing a consistent use-after-free in sys_exit() from gpsd when rebooting: pps pps1: removed -…

▾ Twilightlinux · linux_kernelEPSS 0.26%via NVD
CVE-2022-49328High· 8.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: mt76: fix use-after-free by removing a non-RCU wcid pointer Fixes an issue caught by KASAN about use-after-free in mt76_txq_schedule by protecting mtxq->wcid with rcu_…

In the Linux kernel, the following vulnerability has been resolved: mt76: fix use-after-free by removing a non-RCU wcid pointer Fixes an issue caught by KASAN about use-after-free in mt76_txq_schedule by protecting mtxq->wcid with rcu_…

▾ Twilightlinux · linux_kernelEPSS 0.42%via NVD
CVE-2022-49179High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: block, bfq: don't move oom_bfqq Our test report a UAF: [ 2073.019181] ================================================================== [ 2073.019188] BUG: KASAN: us…

In the Linux kernel, the following vulnerability has been resolved: block, bfq: don't move oom_bfqq Our test report a UAF: [ 2073.019181] ================================================================== [ 2073.019188] BUG: KASAN: us…

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2022-49176High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: bfq: fix use-after-free in bfq_dispatch_request KASAN reports a use-after-free report when doing normal scsi-mq test [69832.239032] ==================================…

In the Linux kernel, the following vulnerability has been resolved: bfq: fix use-after-free in bfq_dispatch_request KASAN reports a use-after-free report when doing normal scsi-mq test [69832.239032] ==================================…

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2022-49129High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: fix crash when startup fails. If the nic fails to start, it is possible that the reset_work has already been scheduled

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: fix crash when startup fails. If the nic fails to start, it is possible that the reset_work has already been scheduled. Ensure the work item is canceled…

▾ Twilightlinux · linux_kernelEPSS 0.27%via NVD
CVE-2021-47646High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: Revert "Revert "block, bfq: honor already-setup queue merges"" A crash [1] happened to be triggered in conjunction with commit 2d52c58b9c9b ("block, bfq: honor already…

In the Linux kernel, the following vulnerability has been resolved: Revert "Revert "block, bfq: honor already-setup queue merges"" A crash [1] happened to be triggered in conjunction with commit 2d52c58b9c9b ("block, bfq: honor already…

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2025-26601High· 7.8
1y ago

A use-after-free flaw was found in X.Org and Xwayland

A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one…

▾ Twilighttigervnc · tigervncEPSS 0.39%via NVD
CVE-2025-26600High· 7.8
1y ago

A use-after-free flaw was found in X.Org and Xwayland

A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.

▾ Twilighttigervnc · tigervncEPSS 0.39%via NVD
CVE-2025-26594High· 7.8
1y ago

A use-after-free flaw was found in X.Org and Xwayland

A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.

▾ Twilighttigervnc · tigervncEPSS 0.39%via NVD
CVE-2025-0622Medium· 6.4
1y ago

A flaw was found in command/gpg

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was…

▾ SunlitEPSS 0.28%via NVD
CVE-2025-21655Medium· 4.7
1y ago

In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but when dropping the reference to the i…

In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but when dropping the reference to the i…

▾ Sunlitlinux · linux_kernelEPSS 0.25%via NVD
CVE-2025-21335High· 7.8CISA KEV0day
1y ago

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_21h2EPSS 1.4%via NVD
CVE-2024-56631High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Fix slab-use-after-free read in sg_release() Fix a use-after-free bug in sg_release(), detected by syzbot with KASAN: BUG: KASAN: slab-use-after-free in loc…

In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Fix slab-use-after-free read in sg_release() Fix a use-after-free bug in sg_release(), detected by syzbot with KASAN: BUG: KASAN: slab-use-after-free in loc…

▾ Twilightlinux · linux_kernelEPSS 0.29%via NVD
CVE-2024-53170High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: block: fix uaf for flush rq while iterating tags blk_mq_clear_flush_rq_mapping() is not called during scsi probe, by checking blk_queue_init_done()

In the Linux kernel, the following vulnerability has been resolved: block: fix uaf for flush rq while iterating tags blk_mq_clear_flush_rq_mapping() is not called during scsi probe, by checking blk_queue_init_done(). However, QUEUE_FLA…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-9680Critical· 9.8CISA KEV0dayPoC
1y ago

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…

▾ Hadalmozilla · firefoxEPSS 23%via NVD
CVE-2024-46786High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF The fscache_cookie_lru_timer is initialized when the fscache module is inserted, but is not de…

In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF The fscache_cookie_lru_timer is initialized when the fscache module is inserted, but is not de…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-41965Medium· 4.2
2y ago

Vim is an open source command line text editor

Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim…

▾ Sunlitneovim · neovimEPSS 0.33%via NVD
CVE-2024-30101High· 7.5
2y ago

Microsoft Office Remote Code Execution Vulnerability

Microsoft Office Remote Code Execution Vulnerability

▾ Twilightmicrosoft · 365_appsEPSS 1.8%via NVD
CVE-2024-30089High· 7.8
2y ago

Microsoft Streaming Service Elevation of Privilege Vulnerability

Microsoft Streaming Service Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · windows_10_1809EPSS 8.1%via NVD
CVE-2024-30086High· 7.8
2y ago

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · windows_10_1507EPSS 1.1%via NVD
CVE-2024-30082High· 7.8
2y ago

Win32k Elevation of Privilege Vulnerability

Win32k Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · windows_10_1507EPSS 1.3%via NVD
CVE-2024-30080Critical· 9.8
2y ago

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

▾ Midnightmicrosoft · windows_10_1507EPSS 43%via NVD
CVE-2024-30062High· 7.8
2y ago

Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability

Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability

▾ Twilightmicrosoft · windows_server_2012EPSS 1.0%via NVD
CVE-2024-36013Medium· 6.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type vo…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type vo…

▾ Sunlitlinux · linux_kernelEPSS 0.48%via NVD
CVE-2021-47335Medium· 5.5
2y ago

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances As syzbot reported, there is an use-after-free issue during f2fs recovery: Use-after-free …

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances As syzbot reported, there is an use-after-free issue during f2fs recovery: Use-after-free …

▾ Sunlitlinux · linux_kernelEPSS 0.23%via NVD
CVE-2022-48670High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to …

In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to …

▾ Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2024-26804High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: prevent perpetual headroom growth syzkaller triggered following kasan splat: BUG: KASAN: use-after-free in __skb_flow_dissect+0x19d1/0x7a50 net/core/fl…

In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: prevent perpetual headroom growth syzkaller triggered following kasan splat: BUG: KASAN: use-after-free in __skb_flow_dissect+0x19d1/0x7a50 net/core/fl…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-26801High· 8.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_error_reset While handling the HCI_EV_HARDWARE_ERROR event, if the underlying BT controller is not responding, the GPI…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_error_reset While handling the HCI_EV_HARDWARE_ERROR event, if the underlying BT controller is not responding, the GPI…

▾ Twilightlinux · linux_kernelEPSS 0.42%via NVD
CVE-2024-26800Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait u…

In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait u…

▾ Midnightlinux · linux_kernelEPSS 0.74%via NVD
CVE-2024-26793High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: gtp: fix use-after-free and null-ptr-deref in gtp_newlink() The gtp_link_ops operations structure for the subsystem must be registered after registering the gtp_net_op…

In the Linux kernel, the following vulnerability has been resolved: gtp: fix use-after-free and null-ptr-deref in gtp_newlink() The gtp_link_ops operations structure for the subsystem must be registered after registering the gtp_net_op…

▾ Twilightlinux · linux_kernelEPSS 0.29%via NVD
CWE-416 vulnerabilities (CVEs) — page 33 · VulnSea