Filtered by CWE-416
Total 6209 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-6645 1 Pdf-xchange 2 Pdf-tools, Pdf-xchange Editor 2025-07-01 N/A
PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26642.
CVE-2025-6644 1 Pdf-xchange 2 Pdf-tools, Pdf-xchange Editor 2025-07-01 N/A
PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26536.
CVE-2025-6640 1 Pdf-xchange 2 Pdf-tools, Pdf-xchange Editor 2025-07-01 N/A
PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26527.
CVE-2025-6661 1 Pdf-xchange 2 Pdf-tools, Pdf-xchange Editor 2025-07-01 N/A
PDF-XChange Editor App Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of App objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26823.
CVE-2025-21366 1 Microsoft 4 365 Apps, Access, Office and 1 more 2025-07-01 7.8 High
Microsoft Access Remote Code Execution Vulnerability
CVE-2025-21386 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-07-01 7.8 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-21387 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-07-01 7.8 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-21362 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-07-01 8.4 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-21345 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-07-01 7.8 High
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2025-21394 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-07-01 7.8 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-21392 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-07-01 7.8 High
Microsoft Office Remote Code Execution Vulnerability
CVE-2025-21397 1 Microsoft 2 365 Apps, Office Long Term Servicing Channel 2025-07-01 7.8 High
Microsoft Office Remote Code Execution Vulnerability
CVE-2024-32502 1 Samsung 16 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 13 more 2025-07-01 8.4 High
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper reference count checking, which can result in a UAF (Use-After-Free) vulnerability.
CVE-2025-6856 2025-06-30 3.3 Low
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_list of the file src/H5FL.c. The manipulation leads to use after free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
CVE-2025-0634 2025-06-30 N/A
Use After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.
CVE-2024-30161 1 Qt 1 Qt 2025-06-30 6.5 Medium
In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.)
CVE-2024-34748 1 Google 1 Android 2025-06-27 8.4 High
In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-40649 1 Google 1 Android 2025-06-27 8.4 High
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-40651 1 Google 1 Android 2025-06-27 8.4 High
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-40669 1 Google 1 Android 2025-06-27 8.4 High
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.