CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,228
Total CVEs
160
Critical
1,913
High
7.9
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 764
2 Google 357
3 Microsoft 258
4 Debian 197
5 Fedoraproject 173
6 Adobe 123
7 Foxit 84
8 Qualcomm 79
9 Apple 68
10 Mozilla 49

All Use After Free CVEs (2,228)

CVE-2021-30604
8.8

This is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome that allows heap corruption. Attacker...

Aug 26, 2021
CVE-2021-30951
8.8

This is a use-after-free vulnerability in Apple's WebKit browser engine that could allow arbitrary code execution when processing malicious web conten...

Aug 24, 2021
CVE-2021-30858
8.8

This is a use-after-free vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content. It...

Aug 24, 2021
CVE-2020-21688
8.8

CVE-2020-21688 is a heap-use-after-free vulnerability in FFmpeg's memory management function that allows attackers to execute arbitrary code on affect...

Aug 10, 2021
CVE-2021-21870
8.8

A use-after-free vulnerability in Foxit PDF Reader's JavaScript engine allows arbitrary code execution when a user opens a malicious PDF file. This af...

Aug 5, 2021
CVE-2021-29970
8.8

This vulnerability allows a malicious webpage to trigger a use-after-free memory corruption in Mozilla browsers when accessibility features are enable...

Aug 5, 2021
CVE-2021-30579
8.8

This is a use-after-free vulnerability in Google Chrome's UI framework that allows remote attackers to potentially exploit heap corruption via a craft...

Aug 3, 2021
CVE-2021-30581
8.8

This is a use-after-free vulnerability in Chrome DevTools that allows heap corruption when a user with a malicious extension visits a crafted HTML pag...

Aug 3, 2021
CVE-2021-30585
8.8

This vulnerability allows remote attackers to potentially exploit heap corruption via a crafted HTML page in Google Chrome on Windows. It affects Chro...

Aug 3, 2021
CVE-2021-30567
8.8

This is a use-after-free vulnerability in Chrome DevTools that could allow heap corruption. Attackers who convince users to open DevTools could potent...

Aug 3, 2021
CVE-2021-30569
8.8

This is a use-after-free vulnerability in SQLite within Google Chrome that allows remote attackers to potentially exploit heap corruption. Attackers c...

Aug 3, 2021
CVE-2021-30573
8.8

This is a use-after-free vulnerability in Chrome's GPU component that allows remote attackers to potentially exploit heap corruption via a crafted HTM...

Aug 3, 2021
CVE-2021-30541
8.8

This is a use-after-free vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to potentially exploit heap corruption. Attackers...

Aug 3, 2021
CVE-2021-30560
8.8

This is a use-after-free vulnerability in Chrome's Blink XSLT processor that allows remote attackers to potentially exploit heap corruption. Attackers...

Aug 3, 2021
CVE-2021-30562
8.8

This vulnerability is a use-after-free memory corruption flaw in Chrome's WebSerial API that allows attackers to potentially execute arbitrary code or...

Aug 3, 2021
CVE-2021-21806
8.8

This is a use-after-free vulnerability in WebKitGTK browser that allows remote code execution when users visit malicious websites. It affects WebKitGT...

Jul 8, 2021
CVE-2021-30555
8.8

This is a use-after-free vulnerability in Google Chrome's Sharing component that allows heap corruption. Attackers can exploit it by tricking users in...

Jul 2, 2021
CVE-2021-28562
8.8

CVE-2021-28562 is a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when processing malicious PDF files w...

Jun 28, 2021
CVE-2021-30550
8.8

This is a use-after-free vulnerability in Chrome's Accessibility component that allows heap corruption. Attackers can exploit it by tricking users int...

Jun 15, 2021
CVE-2021-30552
8.8

This is a use-after-free vulnerability in Chrome's extension system that allows heap corruption. Attackers can exploit it by tricking users into insta...

Jun 15, 2021
CVE-2021-30544
8.8

This is a use-after-free vulnerability in Chrome's Back/Forward Cache (BFCache) that allows remote attackers to potentially exploit heap corruption. A...

Jun 15, 2021
CVE-2021-30546
8.8

This is a use-after-free vulnerability in Chrome's Autofill feature that allows remote attackers to potentially exploit heap corruption. Attackers can...

Jun 15, 2021
CVE-2021-30548
8.8

This is a use-after-free vulnerability in Chrome's Loader component that allows remote attackers to potentially exploit heap corruption. Attackers can...

Jun 15, 2021
CVE-2021-30522
8.8

This is a use-after-free vulnerability in Chrome's WebAudio component that allows remote attackers to potentially exploit heap corruption. Attackers c...

Jun 7, 2021
CVE-2021-30524
8.8

This is a use-after-free vulnerability in Chrome's TabStrip component that allows heap corruption. Attackers can exploit it by convincing users to ins...

Jun 7, 2021
CVE-2021-30528
8.8

This is a use-after-free vulnerability in Chrome's WebAuthentication API on Android that allows heap corruption. Attackers who compromise the renderer...

Jun 7, 2021
CVE-2021-30542
8.8

This is a use-after-free vulnerability in Google Chrome's Tab Strip component that allows heap corruption. Attackers can exploit it by convincing user...

Jun 7, 2021
CVE-2021-30520
8.8

This is a use-after-free vulnerability in Google Chrome's Tab Strip component that allows heap corruption. Attackers can exploit it by convincing user...

Jun 4, 2021
CVE-2021-30510
8.8

This is a use-after-free vulnerability in Chrome's Aura window manager that allows remote attackers to potentially exploit heap corruption. Attackers ...

Jun 4, 2021
CVE-2021-30512
8.8

This is a use-after-free vulnerability in Google Chrome's Notifications feature that allows heap corruption. Attackers who have already compromised th...

Jun 4, 2021
CVE-2021-30514
8.8

This is a use-after-free vulnerability in Chrome's Autofill feature that allows a remote attacker who has already compromised the renderer process to ...

Jun 4, 2021
CVE-2021-29256
8.8

This vulnerability in the Arm Mali GPU kernel driver allows unprivileged users to access freed memory, potentially leading to information disclosure o...

May 24, 2021
CVE-2021-3518
8.8

A use-after-free vulnerability in libxml2 versions before 2.9.11 allows attackers to submit crafted XML files to applications using this library, pote...

May 18, 2021
CVE-2021-21822
8.8

A use-after-free vulnerability in Foxit PDF Reader's JavaScript engine allows arbitrary code execution when users open malicious PDF files. This affec...

May 10, 2021
CVE-2021-28663
8.8

This vulnerability in the Arm Mali GPU kernel driver allows attackers to escalate privileges or disclose sensitive information due to mishandled GPU m...

May 10, 2021
CVE-2021-21232
8.8

This is a use-after-free vulnerability in Chrome's Dev Tools that allows remote attackers to potentially exploit heap corruption via a crafted HTML pa...

Apr 30, 2021
CVE-2021-21203
8.8

This is a use-after-free vulnerability in Google Chrome's Blink rendering engine that allows remote attackers to potentially exploit heap corruption. ...

Apr 26, 2021
CVE-2021-21213
8.8

This is a use-after-free vulnerability in Chrome's WebMIDI implementation that allows remote attackers to potentially exploit heap corruption. Attacke...

Apr 26, 2021
CVE-2021-21194
8.8

This vulnerability is a use-after-free memory corruption flaw in Google Chrome's screen sharing feature. It allows remote attackers to potentially exe...

Apr 9, 2021
CVE-2021-26411
8.8

CVE-2021-26411 is a memory corruption vulnerability in Internet Explorer that allows remote attackers to execute arbitrary code on affected systems. I...

Mar 11, 2021
CVE-2021-21179
8.8

This is a use-after-free vulnerability in Chrome's Network Internals component on Linux systems. It allows remote attackers to potentially execute arb...

Mar 9, 2021
CVE-2021-21188
8.8

This is a use-after-free vulnerability in Chrome's Blink rendering engine that allows remote attackers to potentially execute arbitrary code via a cra...

Mar 9, 2021
CVE-2021-21167
8.8

This is a use-after-free vulnerability in Google Chrome's bookmarks feature that allows remote attackers to potentially exploit heap corruption. Attac...

Mar 9, 2021
CVE-2021-21162
8.8

This vulnerability is a use-after-free memory corruption flaw in Chrome's WebRTC component that allows remote attackers to potentially execute arbitra...

Mar 9, 2021
CVE-2020-13558
8.8

This vulnerability allows remote code execution through a use-after-free flaw in WebKitGTK's AudioSourceProviderGStreamer component. Attackers can exp...

Mar 3, 2021
CVE-2021-21035
8.8

CVE-2021-21035 is a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF fil...

Feb 11, 2021
CVE-2021-21021
8.8

CVE-2021-21021 is a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF fil...

Feb 11, 2021
CVE-2021-21028
8.8

CVE-2021-21028 is a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF fil...

Feb 11, 2021
CVE-2021-21033
8.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF fi...

Feb 11, 2021
CVE-2021-21119
8.8

This is a use-after-free vulnerability in Chrome's media component that allows a remote attacker who has already compromised the renderer process to p...

Feb 9, 2021

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,228 CVEs classified as CWE-416, with 160 rated critical and 1,913 rated high severity. The average CVSS score for Use After Free vulnerabilities is 7.9.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free