CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,184
Total CVEs
152
Critical
1,877
High
7.9
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 760
2 Google 343
3 Microsoft 256
4 Debian 189
5 Fedoraproject 166
6 Adobe 116
7 Foxit 84
8 Qualcomm 78
9 Apple 62
10 Mozilla 47

All Use After Free CVEs (2,184)

CVE-2024-4764
9.8

A use-after-free vulnerability in Firefox's WebRTC audio input handling allows multiple threads to claim the same audio connection, potentially leadin...

May 14, 2024
CVE-2024-21334
9.8

CVE-2024-21334 is a use-after-free vulnerability in Open Management Infrastructure (OMI) that allows remote attackers to execute arbitrary code with r...

Mar 12, 2024
CVE-2023-43552
9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption when processing specially crafte...

Mar 4, 2024
CVE-2024-23807
9.8

This CVE describes a use-after-free vulnerability in Apache Xerces C++ XML parser versions 3.0.0 through 3.2.4. When processing external DTDs, the par...

Feb 29, 2024
CVE-2020-36773
9.8

This vulnerability in Ghostscript allows attackers to execute arbitrary code or cause denial of service by exploiting out-of-bounds write and use-afte...

Feb 4, 2024
CVE-2023-37117
9.8

A heap-use-after-free vulnerability in live555 media server allows attackers to execute arbitrary code or cause denial of service by sending specially...

Jan 12, 2024
CVE-2023-40414
9.8

This is a critical use-after-free vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web co...

Jan 10, 2024
CVE-2024-22088
9.8

CVE-2024-22088 is a critical use-after-free vulnerability in Lotos WebServer that allows remote attackers to execute arbitrary code or cause denial of...

Jan 5, 2024
CVE-2023-46850
9.8

CVE-2023-46850 is a use-after-free vulnerability in OpenVPN that can lead to memory corruption, information disclosure, or remote code execution when ...

Nov 11, 2023
CVE-2023-38703
9.8

CVE-2023-38703 is a use-after-free vulnerability in PJSIP's SRTP implementation that occurs when higher-level media transport isn't properly synchroni...

Oct 6, 2023
CVE-2023-5172
9.8

This CVE describes a use-after-free vulnerability in Firefox's Ion Engine hashtable implementation. An attacker could exploit this to execute arbitrar...

Sep 27, 2023
CVE-2023-5174
9.8

This CVE describes a use-after-free vulnerability in Firefox/Thunderbird on Windows when run in non-standard configurations (like using 'runas'). If e...

Sep 27, 2023
CVE-2023-39453
9.8

A use-after-free vulnerability in Accusoft ImageGear's TIFF parsing functionality allows arbitrary code execution when processing specially crafted fi...

Sep 25, 2023
CVE-2023-38598
9.8

This CVE-2023-38598 is a use-after-free vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel priv...

Jul 28, 2023
CVE-2023-29824
9.8

CVE-2023-29824 is a use-after-free vulnerability in the Py_FindObjects() function in SciPy versions before 1.8.0. This could potentially allow attacke...

Jul 6, 2023
CVE-2023-32412
9.8

This is a critical use-after-free vulnerability in Apple operating systems that allows remote attackers to cause application crashes or execute arbitr...

Jun 23, 2023
CVE-2023-32387
9.8

This is a critical use-after-free vulnerability in macOS that allows remote attackers to cause application crashes or execute arbitrary code on affect...

Jun 23, 2023
CVE-2023-21096
9.8

This is a critical use-after-free vulnerability in Android's attribution processor that allows remote code execution without user interaction. Attacke...

Apr 19, 2023
CVE-2023-23392
9.8

CVE-2023-23392 is a critical remote code execution vulnerability in the Windows HTTP Protocol Stack (http.sys) that allows unauthenticated attackers t...

Mar 14, 2023
CVE-2023-24734
9.8

This critical vulnerability in PMB v7.4.6 allows attackers to upload malicious image files through the camera_upload.php component, leading to arbitra...

Mar 6, 2023
CVE-2021-33391
9.8

CVE-2021-33391 is a use-after-free vulnerability in HTACG HTML Tidy that allows attackers to execute arbitrary code via the -g option in the CleanNode...

Feb 17, 2023
CVE-2022-28350
9.8

This vulnerability in Arm Mali GPU Kernel Driver allows attackers to trigger a use-after-free condition through improper GPU operations, potentially l...

May 19, 2022
CVE-2022-28348
9.8

This vulnerability in Arm Mali GPU kernel drivers allows improper GPU memory operations to reach a use-after-free situation. Attackers can exploit thi...

May 19, 2022
CVE-2022-1795
9.8

CVE-2022-1795 is a use-after-free vulnerability in GPAC multimedia framework that allows attackers to execute arbitrary code or cause denial of servic...

May 18, 2022
CVE-2022-29794
9.8

CVE-2022-29794 is a Use After Free vulnerability in the frame scheduling module of Huawei HarmonyOS and EMUI devices. This vulnerability allows attack...

May 13, 2022
CVE-2022-1212
9.8

CVE-2022-1212 is a use-after-free vulnerability in mruby's str_escape function that could allow attackers to execute arbitrary code. This affects appl...

Apr 5, 2022
CVE-2022-22641
9.8

CVE-2022-22641 is a use-after-free vulnerability in Apple operating systems that allows malicious applications to gain elevated privileges. This affec...

Mar 18, 2022
CVE-2022-0559
9.8

This is a use-after-free vulnerability in radare2, a popular reverse engineering framework. Attackers can exploit this to execute arbitrary code or ca...

Feb 16, 2022
CVE-2022-0139
9.8

CVE-2022-0139 is a use-after-free vulnerability in radare2, a popular reverse engineering framework. This allows attackers to execute arbitrary code o...

Feb 8, 2022
CVE-2021-45701
9.8

This vulnerability in the tremor-script Rust crate allows use-after-free memory corruption when performing patch operations. Attackers could exploit t...

Dec 27, 2021
CVE-2021-37045
9.8

This CVE describes a use-after-free vulnerability in Huawei smartphones that allows attackers to execute arbitrary kernel-mode code. Successful exploi...

Dec 8, 2021
CVE-2021-22930
9.8

CVE-2021-22930 is a use-after-free vulnerability in Node.js that allows memory corruption attacks. An attacker could exploit this to execute arbitrary...

Oct 7, 2021
CVE-2021-1976
9.8

This critical vulnerability in Qualcomm Snapdragon chipsets allows remote code execution due to a use-after-free memory corruption flaw in Wi-Fi P2P (...

Sep 17, 2021
CVE-2021-1864
9.8

This is a use-after-free vulnerability in Apple's iOS, iPadOS, watchOS, and tvOS that allows an attacker with JavaScript execution capability to poten...

Sep 8, 2021
CVE-2021-38383
9.8

CVE-2021-38383 is a use-after-free vulnerability in OwnTone's net_bind() function that allows attackers to execute arbitrary code or cause denial of s...

Aug 10, 2021
CVE-2021-22348
9.8

This is a critical use-after-free vulnerability (CWE-416) in Huawei smartphones that allows attackers to execute arbitrary code. Successful exploitati...

Jun 30, 2021
CVE-2021-27649
9.8

This is a critical use-after-free vulnerability in Synology DiskStation Manager's file transfer protocol component that allows remote attackers to exe...

Jun 23, 2021
CVE-2021-24037
9.8

This CVE describes a use-after-free vulnerability in the Hermes JavaScript engine that could allow attackers to execute arbitrary code by crafting mal...

Jun 15, 2021
CVE-2020-23302
9.8

This is a critical heap-use-after-free vulnerability in JerryScript's string handling that allows memory corruption. Attackers can exploit this to exe...

Jun 10, 2021
CVE-2021-30474
9.8

CVE-2021-30474 is a use-after-free vulnerability in libaom's grain_table.c that allows memory corruption. Attackers can exploit this to execute arbitr...

Jun 2, 2021
CVE-2021-33574
9.8

This CVE describes a use-after-free vulnerability in the GNU C Library (glibc) mq_notify function affecting versions 2.32 and 2.33. Attackers could ex...

May 25, 2021
CVE-2020-36329
9.8

CVE-2020-36329 is a use-after-free vulnerability in libwebp that allows attackers to execute arbitrary code or cause denial of service. This affects a...

May 21, 2021
CVE-2021-31166
9.8

CVE-2021-31166 is a critical remote code execution vulnerability in the Microsoft HTTP Protocol Stack (http.sys) that allows unauthenticated attackers...

May 11, 2021
CVE-2021-20231
9.8

This CVE-2021-20231 is a critical use-after-free vulnerability in GnuTLS that occurs when a client sends a key_share extension, potentially leading to...

Mar 12, 2021
CVE-2020-1900
9.8

CVE-2020-1900 is a use-after-free vulnerability in HHVM's object unserialization that occurs when dynamic properties are not properly pre-reserved in ...

Mar 11, 2021
CVE-2020-11272
9.8

This is a use-after-free vulnerability in Qualcomm Snapdragon chipsets that allows attackers to execute arbitrary code or cause denial of service. It ...

Feb 22, 2021
CVE-2021-26689
9.8

This vulnerability is a use-after-free flaw in LG mobile devices' USB laf gadget driver that could allow local attackers to execute arbitrary code wit...

Feb 4, 2021
CVE-2020-26972
9.8

This is a use-after-free vulnerability in Firefox's WebGL implementation where IPC actors can outlive their managers, leading to memory corruption. At...

Jan 7, 2021
CVE-2020-35876
9.8

This vulnerability in the Rio crate for Rust allows attackers to leak structs, potentially exposing sensitive information, causing use-after-free cond...

Dec 31, 2020
CVE-2020-35870
9.8

CVE-2020-35870 is a use-after-free vulnerability in the rusqlite crate for Rust that allows memory corruption through the Auxdata API. This can lead t...

Dec 31, 2020

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,184 CVEs classified as CWE-416, with 152 rated critical and 1,877 rated high severity. The average CVSS score for Use After Free vulnerabilities is 7.9.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free