CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,235
Total CVEs
160
Critical
1,920
High
7.9
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 766
2 Google 359
3 Microsoft 258
4 Debian 198
5 Fedoraproject 173
6 Adobe 123
7 Foxit 84
8 Qualcomm 79
9 Apple 68
10 Mozilla 49

All Use After Free CVEs (2,235)

CVE-2024-25985
8.4

CVE-2024-25985 is a use-after-free vulnerability in the bigo_unlocked_ioctl function of bigo.c that allows local privilege escalation without requirin...

Mar 11, 2024
CVE-2023-43546
8.4

This vulnerability allows memory corruption when invoking the HGSL IOCTL context create function in Qualcomm GPU drivers. Attackers could potentially ...

Mar 4, 2024
CVE-2023-6143
8.4

A use-after-free vulnerability in Arm Mali GPU kernel drivers allows local non-privileged users to exploit a race condition under heavy system load to...

Mar 4, 2024
CVE-2021-46973
8.4

This is a use-after-free vulnerability in the Linux kernel's Qualcomm IPC Router (QRTR) subsystem when used with MHI (Modem Host Interface). It allows...

Feb 27, 2024
CVE-2023-43514
8.4

This vulnerability allows memory corruption through improper handling of IOCTL calls for internal memory mapping/unmapping operations in Qualcomm comp...

Jan 2, 2024
CVE-2023-33108
8.4

This vulnerability allows memory corruption in Qualcomm's Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued....

Jan 2, 2024
CVE-2023-33039
8.4

This vulnerability allows memory corruption in automotive display systems when destroying image handles created using the connected display driver. At...

Oct 3, 2023
CVE-2023-33021
8.4

This CVE describes a memory corruption vulnerability in Qualcomm graphics drivers that occurs while processing user packets for command submission. At...

Sep 5, 2023
CVE-2023-21672
8.4

This CVE describes a memory corruption vulnerability in Qualcomm's audio subsystem that occurs during concurrent tunnel playback or recording sessions...

Jul 4, 2023
CVE-2022-22071
8.4

This is a use-after-free vulnerability in Qualcomm Snapdragon chipsets that allows attackers to execute arbitrary code or cause denial of service. It ...

Jun 14, 2022
CVE-2022-22090
8.4

This is a use-after-free vulnerability in Qualcomm Snapdragon audio components that allows memory corruption. Attackers could potentially execute arbi...

Jun 14, 2022
CVE-2021-30334
8.4

This CVE describes a use-after-free vulnerability in Qualcomm Snapdragon chipsets where DRM file status isn't properly checked after file structure is...

Jun 14, 2022
CVE-2021-35115
8.4

This vulnerability in Qualcomm Snapdragon chipsets allows attackers to execute arbitrary code or cause denial of service through a use-after-free cond...

Apr 1, 2022
CVE-2021-30262
8.4

This vulnerability allows improper memory access due to improper socket state validation in Qualcomm Snapdragon chipsets. Attackers could potentially ...

Jan 3, 2022
CVE-2021-30315
8.4

This vulnerability in Qualcomm Snapdragon Auto chipsets allows attackers to execute arbitrary code or cause denial of service through a use-after-free...

Oct 20, 2021
CVE-2021-1947
8.4

This CVE describes a use-after-free vulnerability in Qualcomm's kernel graphics driver affecting multiple Snapdragon platforms. Attackers could exploi...

Sep 17, 2021
CVE-2021-1891
8.4

This vulnerability is a use-after-free flaw in Qualcomm audio drivers affecting multiple Snapdragon platforms. It allows attackers to potentially exec...

May 7, 2021
CVE-2021-1905
8.4

CVE-2021-1905 is a use-after-free vulnerability in Qualcomm Snapdragon chipsets that allows attackers to potentially execute arbitrary code or cause d...

May 7, 2021
CVE-2020-11234
8.4

This CVE describes a use-after-free vulnerability in Qualcomm Snapdragon chipsets where a socket freed by one thread can still be accessed by another ...

Apr 7, 2021
CVE-2024-43574
8.3

This vulnerability in Microsoft Speech API (SAPI) allows remote attackers to execute arbitrary code on affected systems by sending specially crafted r...

Oct 8, 2024
CVE-2024-21399
8.3

This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems. Attackers could exploit t...

Feb 2, 2024
CVE-2024-21385
8.3

This vulnerability in Microsoft Edge allows attackers to gain elevated privileges on affected systems by exploiting a use-after-free memory corruption...

Jan 26, 2024
CVE-2023-36741
8.3

This vulnerability in Microsoft Edge (Chromium-based) allows attackers to gain elevated privileges on affected systems. It affects users running vulne...

Aug 26, 2023
CVE-2024-6519
8.2

A use-after-free vulnerability in QEMU's LSI53C895A SCSI Host Bus Adapter emulation allows attackers to cause a denial of service or potentially escap...

Oct 21, 2024
CVE-2024-37030
8.2

CVE-2024-37030 is a use-after-free vulnerability in OpenHarmony v4.0.0 and earlier that allows remote attackers to execute arbitrary code in pre-insta...

Jul 2, 2024
CVE-2024-21860
8.2

CVE-2024-21860 is a use-after-free vulnerability in OpenHarmony v4.0.0 and earlier that allows an adjacent attacker to execute arbitrary code in any a...

Feb 2, 2024
CVE-2021-3750
8.2

A DMA reentrancy vulnerability in QEMU's USB EHCI controller emulation allows malicious guests to write crafted data to controller registers during pa...

May 2, 2022
CVE-2022-1071
8.2

CVE-2022-1071 is a use-after-free vulnerability in mrb_vm_exec in mruby, a lightweight Ruby implementation. This vulnerability allows attackers to exe...

Mar 26, 2022
CVE-2020-25632
8.2

This CVE-2020-25632 vulnerability in GRUB2 allows attackers to unload kernel modules that other modules depend on, creating a use-after-free condition...

Mar 3, 2021
CVE-2025-46205
8.1

A heap-use-after-free vulnerability in PoDoFo PDF library's PdfTokenizer::ReadDictionary function allows attackers to cause Denial of Service (DoS) by...

Oct 1, 2025
CVE-2025-36854
8.1

A race condition in EOL ASP.NET versions when closing HTTP/3 streams while writing response bodies can cause use-after-free memory corruption, potenti...

Sep 8, 2025
CVE-2025-49735
8.1

CVE-2025-49735 is a use-after-free vulnerability in Windows KDC Proxy Service (KPSSVC) that allows unauthorized attackers to execute arbitrary code re...

Jul 8, 2025
CVE-2025-1290
8.1

A race condition use-after-free vulnerability in ChromeOS Kernel 5.4's virtio_transport_space_update function allows concurrent allocation and freeing...

Apr 17, 2025
CVE-2025-26670
8.1

A use-after-free vulnerability in Windows LDAP allows unauthorized attackers to execute arbitrary code remotely over a network. This affects Windows s...

Apr 8, 2025
CVE-2025-30232
8.1

A use-after-free vulnerability in Exim versions 4.96 through 4.98.1 allows users with command-line access to escalate privileges. This affects systems...

Mar 28, 2025
CVE-2025-24064
8.1

This is a use-after-free vulnerability in DNS Server that allows unauthorized attackers to execute arbitrary code remotely. It affects systems running...

Mar 11, 2025
CVE-2025-0997
8.1

This is a use-after-free vulnerability in Google Chrome's navigation component that allows remote attackers to potentially exploit heap corruption via...

Feb 15, 2025
CVE-2022-49043
8.1

CVE-2022-49043 is a use-after-free vulnerability in libxml2's xmlXIncludeAddNode function that allows attackers to execute arbitrary code or cause den...

Jan 26, 2025
CVE-2025-21295
8.1

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a use-after-free flaw in the SPNEGO Extended Ne...

Jan 14, 2025
CVE-2025-21297
8.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems with Remote Desktop Services enabled. Attackers can exploit th...

Jan 14, 2025
CVE-2025-21224
8.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Line Printer Daemon (LPD) service. Attackers can e...

Jan 14, 2025
CVE-2021-32589
8.1

A use-after-free vulnerability in FortiManager and FortiAnalyzer's fgfmsd daemon allows remote unauthenticated attackers to execute arbitrary code as ...

Dec 19, 2024
CVE-2024-49132
8.1

This vulnerability allows attackers to execute arbitrary code on Windows systems through Remote Desktop Services. It affects Windows servers and works...

Dec 12, 2024
CVE-2024-49126
8.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a use-after-free bug (CWE-416) in the Local Secu...

Dec 12, 2024
CVE-2024-49128
8.1

This vulnerability in Windows Remote Desktop Services allows unauthorized attackers to execute arbitrary code remotely by exploiting improper memory l...

Dec 12, 2024
CVE-2024-49116
8.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running vulnerable Remote Desktop Services. Attackers can pote...

Dec 12, 2024
CVE-2024-49118
8.1

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted ...

Dec 12, 2024
CVE-2024-49122
8.1

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted ...

Dec 12, 2024
CVE-2024-49106
8.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems with Remote Desktop Services enabled, potentially gaining full...

Dec 12, 2024
CVE-2024-49108
8.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running vulnerable Remote Desktop Services. Attackers can expl...

Dec 12, 2024

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,235 CVEs classified as CWE-416, with 160 rated critical and 1,920 rated high severity. The average CVSS score for Use After Free vulnerabilities is 7.9.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free