CWE-416: Use After Free
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
Yearly Trend
Top Affected Vendors
All Use After Free CVEs (2,209)
This CVE describes a use-after-free vulnerability (CWE-416) in Apple operating systems that allows malicious applications to elevate privileges. It af...
Jan 27, 2025This CVE describes a use-after-free vulnerability in FreeBSD's umtx (user mutex) subsystem where concurrent destruction of anonymous shared memory map...
Sep 5, 2024CVE-2021-33796 is a use-after-free vulnerability in MuJS's regexp source property access that can lead to denial of service. This affects applications...
Jul 7, 2023This is a use-after-free vulnerability in Microsoft Graphics Component that allows an authenticated attacker to execute arbitrary code with elevated p...
Oct 14, 2025This CVE describes a critical vulnerability in Redis where authenticated users can execute specially crafted Lua scripts to manipulate the garbage col...
Oct 3, 2025This CVE describes a use-after-free vulnerability in FreeRDP's clipboard handling for X11 clients. When FreeRDP automatically reconnects, one thread f...
Feb 25, 2026This is a use-after-free vulnerability in FreeRDP's X11 client implementation where the RDPGFX DVC thread can access a freed window pointer while the ...
Feb 25, 2026This is a use-after-free vulnerability in FreeRDP's X11 client where a cached XImage continues to reference freed memory. Attackers could potentially ...
Feb 25, 2026A use-after-free vulnerability in Firefox's JavaScript engine allows attackers to execute arbitrary code by tricking users into visiting malicious web...
Feb 24, 2026This CVE describes a use-after-free vulnerability in Firefox's DOM Bindings (WebIDL) component that could allow an attacker to execute arbitrary code....
Feb 24, 2026A use-after-free vulnerability in Firefox's audio/video playback component allows attackers to execute arbitrary code or cause crashes. This affects F...
Feb 24, 2026A use-after-free vulnerability in Firefox's JavaScript garbage collector component allows attackers to execute arbitrary code by manipulating memory a...
Feb 24, 2026This CVE describes a use-after-free vulnerability in Firefox's JavaScript JIT compiler that could allow arbitrary code execution. It affects Firefox v...
Feb 24, 2026A use-after-free vulnerability in Firefox's JavaScript JIT engine allows attackers to execute arbitrary code by tricking users into visiting malicious...
Feb 24, 2026This vulnerability allows remote code execution through malicious web pages containing specially crafted GPU shader code. When loaded, it triggers a u...
Jan 24, 2026CVE-2026-0794 is a use-after-free vulnerability in ALGO 8180 IP Audio Alerter devices that allows remote attackers to execute arbitrary code without a...
Jan 23, 2026This is a use-after-free vulnerability in FreeRDP's X11 client graphics handling that allows a malicious RDP server to trigger heap corruption in the ...
Jan 19, 2026CVE-2026-23884 is a use-after-free vulnerability in FreeRDP clients where offscreen bitmap deletion leaves a pointer to freed memory. A malicious RDP ...
Jan 19, 2026This is a critical heap use-after-free vulnerability in FreeRDP that allows remote code execution. Attackers can exploit this to execute arbitrary cod...
Jan 14, 2026FreeImage 3.18.0 contains a use-after-free vulnerability in the TARGA image parser that allows attackers to execute arbitrary code or cause denial of ...
Jan 14, 2026A use-after-free vulnerability in the JavaScript Engine component allows attackers to execute arbitrary code or cause denial of service. This affects ...
Jan 13, 2026A use-after-free vulnerability in Firefox's Disability Access APIs allows attackers to execute arbitrary code by manipulating freed memory. This affec...
Dec 18, 2025A use-after-free vulnerability in the Gecko Media Plugins (GMP) component of Firefox and Thunderbird allows attackers to execute arbitrary code or cau...
Dec 9, 2025A use-after-free vulnerability in the WebRTC signaling component allows attackers to execute arbitrary code or cause a crash by manipulating memory af...
Dec 9, 2025CVE-2025-57108 is a critical heap use-after-free vulnerability in Kitware VTK's GLTF file parser that allows remote code execution or application cras...
Oct 31, 2025A use-after-free vulnerability in Firefox's WebGPU implementation allows a compromised child process to trigger memory corruption in the GPU or browse...
Oct 28, 2025A use-after-free vulnerability in Thunderbird's native messaging API on Windows allows memory corruption when web extensions interact with the API. Th...
Oct 14, 2025This is a use-after-free vulnerability in Firefox and Thunderbird's MediaTrackGraphImpl::GetInstance() function. It allows attackers to execute arbitr...
Oct 14, 2025CVE-2025-22408 is a critical use-after-free vulnerability in Android's Bluetooth stack that allows remote code execution without user interaction. Att...
Aug 26, 2025This critical vulnerability in Android's Bluetooth stack allows remote attackers to execute arbitrary code without user interaction. A use-after-free ...
Aug 26, 2025This critical vulnerability in Android's Bluetooth stack allows remote attackers to execute arbitrary code without user interaction or additional priv...
Aug 26, 2025A use-after-free vulnerability in libcoap's coap_delete_pdu_lkd function allows memory corruption when applications misuse the library. This could lea...
Aug 14, 2025A use-after-free vulnerability (CWE-416) in Apple operating systems allows attackers to cause unexpected application termination. This affects macOS a...
Jul 30, 2025A Use After Free vulnerability in Samsung's rLottie animation library allows remote attackers to execute arbitrary code by exploiting memory corruptio...
Jun 30, 2025A use-after-free vulnerability in Firefox's FontFaceSet implementation allows memory corruption that could lead to arbitrary code execution. This affe...
Jun 24, 2025CVE-2023-26226 is a use-after-free memory corruption vulnerability in Yandex Browser that allows attackers to execute arbitrary code or cause denial o...
May 30, 2025A heap buffer overflow vulnerability in Exiv2 versions 0.28.0 through 0.28.4 allows attackers to potentially execute arbitrary code by tricking victim...
Feb 18, 2025A use-after-free vulnerability in Firefox and Thunderbird allows attackers to cause potentially exploitable crashes via crafted XSLT data. This affect...
Feb 4, 2025This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by exploiting a use-after-free bug in the Reliable Mu...
Jan 14, 2025This critical vulnerability in Windows OLE (Object Linking and Embedding) allows remote attackers to execute arbitrary code on affected systems by tri...
Jan 14, 2025This CVE describes a use-after-free vulnerability in ROS2 Nav2's AMCL (Adaptive Monte Carlo Localization) component. Attackers can remotely trigger me...
Dec 6, 2024This CVE describes a use-after-free vulnerability in ROS2 Nav2's AMCL process that can be triggered remotely by sending a request to change the dynami...
Dec 6, 2024CVE-2024-38921 is a critical use-after-free vulnerability in ROS2 Nav2's AMCL component that allows remote attackers to potentially execute arbitrary ...
Dec 6, 2024This CVE describes a use-after-free vulnerability in ROS2 Nav2's AMCL process that can be triggered remotely by sending a request to change the dynami...
Dec 6, 2024This critical vulnerability allows remote attackers to execute arbitrary code by exploiting a use-after-free flaw in Firefox's animation timeline impl...
Oct 9, 2024A servicing stack vulnerability in Windows 10 version 1507 has rolled back previously fixed security patches for optional components, allowing attacke...
Sep 10, 2024This critical vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Line Printer Daemon (LPD) service. Attack...
Aug 13, 2024This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted packets to the Reliable ...
Aug 13, 2024CVE-2024-30080 is a critical remote code execution vulnerability in Microsoft Message Queuing (MSMQ) that allows unauthenticated attackers to execute ...
Jun 11, 2024This is a use-after-free vulnerability in the Linux kernel's NVMe over RDMA subsystem. An attacker could exploit this to cause kernel memory corruptio...
May 21, 2024About Use After Free (CWE-416)
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
Our database tracks 2,209 CVEs classified as CWE-416, with 154 rated critical and 1,900 rated high severity. The average CVSS score for Use After Free vulnerabilities is 7.9.
External reference: View CWE-416 on MITRE CWE →
Monitor Use After Free Vulnerabilities
Get alerted when new Use After Free CVEs affect your infrastructure.
Start Monitoring Free