VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2020-36785High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a …

▾ Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2021-46973High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Avoid potential use after free in MHI send It is possible that the MHI ul_callback will be invoked immediately following the queueing of the skb for transmi…

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Avoid potential use after free in MHI send It is possible that the MHI ul_callback will be invoked immediately following the queueing of the skb for transmi…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2021-46969High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Fix invalid error returning in mhi_queue mhi_queue returns an error when the doorbell is not accessible in the current state

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Fix invalid error returning in mhi_queue mhi_queue returns an error when the doorbell is not accessible in the current state. This can happen when the …

▾ Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2021-46958High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race between transaction aborts and fsyncs leading to use-after-free There is a race between a task aborting a transaction during a commit, a task doing an …

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race between transaction aborts and fsyncs leading to use-after-free There is a race between a task aborting a transaction during a commit, a task doing an …

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2021-46936High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net: fix use-after-free in tw_timer_handler A real world panic issue was found as follow in Linux 5.4. BUG: unable to handle page fault for address: ffffde49a863d…

In the Linux kernel, the following vulnerability has been resolved: net: fix use-after-free in tw_timer_handler A real world panic issue was found as follow in Linux 5.4. BUG: unable to handle page fault for address: ffffde49a863d…

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2021-46933High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear. ffs_data_clear is indirectly called from both ffs_fs_kill_sb and ffs_ep0_release, so it ends up being called tw…

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear. ffs_data_clear is indirectly called from both ffs_fs_kill_sb and ffs_ep0_release, so it ends up being called tw…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2021-46929High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: sctp: use call_rcu to free endpoint This patch is to delay the endpoint free by calling call_rcu() to fix another use-after-free issue in sctp_sock_dump(): BUG: KAS…

In the Linux kernel, the following vulnerability has been resolved: sctp: use call_rcu to free endpoint This patch is to delay the endpoint free by calling call_rcu() to fix another use-after-free issue in sctp_sock_dump(): BUG: KAS…

▾ Twilightlinux · linux_kernelEPSS 0.26%via NVD
CVE-2019-25162High· 7.8PoC
2y ago

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after f…

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after f…

▾ Midnightlinux · linux_kernelEPSS 0.38%via NVD
CVE-2023-52469High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: drivers/amd/pm: fix a use-after-free in kv_parse_power_table When ps allocated by kzalloc equals to NULL, kv_parse_power_table frees adev->pm.dpm.ps that allocated bef…

In the Linux kernel, the following vulnerability has been resolved: drivers/amd/pm: fix a use-after-free in kv_parse_power_table When ps allocated by kzalloc equals to NULL, kv_parse_power_table frees adev->pm.dpm.ps that allocated bef…

▾ Twilightlinux · linux_kernelEPSS 0.29%via NVD
CVE-2024-26598High· 8.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF scenario in the case of an LPI translation cache hit racing with an operati…

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF scenario in the case of an LPI translation cache hit racing with an operati…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-26592Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new TCP connection and its disconnection

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new TCP connection and its disconnection. It leads to UAF on `struct tcp_trans…

▾ Midnightlinux · linux_kernelEPSS 0.97%via NVD
CVE-2023-52447High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Defer the free of inner map when necessary When updating or deleting an inner map in map array or map htab, the map may still be accessed by non-sleepable program…

In the Linux kernel, the following vulnerability has been resolved: bpf: Defer the free of inner map when necessary When updating or deleting an inner map in map array or map htab, the map may still be accessed by non-sleepable program…

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2024-26582Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt…

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt…

▾ Midnightlinux · linux_kernelEPSS 0.71%via NVD
CVE-2023-52438High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used during the shrinker's callback, which means that using alloc->vma pointer isn't safe as it …

In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used during the shrinker's callback, which means that using alloc->vma pointer isn't safe as it …

▾ Twilightlinux · linux_kernelEPSS 0.29%via NVD
CVE-2024-1086High· 7.8CISA KEVPoC
2y ago

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

▾ Abyssalnetapp · h300s_firmwareEPSS 28%via NVD
CVE-2024-0775Medium· 6.7
2y ago

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, l…

▾ Sunlitlinux · linux_kernelEPSS 0.22%via NVD
CVE-2022-2586Medium· 5.3CISA KEV0dayPoC
2y ago

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

▾ Midnightlinux · linux_kernelEPSS 10%via NVD
CVE-2023-48706Low· 3.6
2y ago

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that t…

▾ Sunlitneovim · neovimEPSS 0.54%via NVD
CVE-2023-48231Low· 3.9
2y ago

Vim is an open source command line text editor

Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not been shown to be viable. This issue has been addressed in c…

▾ Sunlitvim · vimEPSS 0.67%via NVD
CVE-2023-46850Critical· 9.8
2y ago

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

▾ Midnightopenvpn · openvpnEPSS 2.0%via NVD
CVE-2023-46246Medium· 4.0
2y ago

Vim is an improved version of the good old UNIX editor Vi

Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_grow_inner` in in the file `src/alloc.c` at line 748, which is freed in the file `src/ex_docmd.c` in the function `do_…

▾ Sunlitvim · vimEPSS 0.37%via NVD
CVE-2023-5574High· 7.0
2y ago

A use-after-free flaw was found in xorg-x11-server-Xvfb

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped f…

▾ Twilightx.org · x_serverEPSS 0.62%via NVD
CVE-2023-5380Medium· 4.7
2y ago

A use-after-free flaw was found in the xorg-x11-server

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped fro…

▾ Sunlitx.org · x_serverEPSS 0.71%via NVD
CVE-2023-5535High· 7.8⚖ disputed
2y ago

Use After Free in GitHub repository vim/vim prior to v9.0.2010.

Use After Free in GitHub repository vim/vim prior to v9.0.2010.

▾ Twilightneovim · neovimEPSS 0.51%via NVD
CVE-2023-4806Medium· 5.9
3y ago

A flaw has been identified in glibc

A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the …

▾ Sunlitgnu · glibcEPSS 1.6%via NVD
CVE-2023-4622High· 7.8PoC
3y ago

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without lock…

▾ Midnightlinux · linux_kernelEPSS 0.61%via NVD
CVE-2023-4244High· 7.8
3y ago

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set elemen…

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set elemen…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2023-4752High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

▾ Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-4750High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

▾ Twilightneovim · neovimEPSS 0.53%via NVD
CVE-2023-4733High· 7.8
3y ago

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

▾ Twilightneovim · neovimEPSS 0.54%via NVD
CWE-416 vulnerabilities (CVEs) — page 35 · VulnSea