CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,308
Total CVEs
181
Critical
1,972
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 767
2 Google 387
3 Microsoft 259
4 Debian 227
5 Fedoraproject 194
6 Adobe 131
7 Foxit 84
8 Qualcomm 83
9 Apple 75
10 Mozilla 53

All Use After Free CVEs (2,308)

CVE-2024-56658
7.8

This is a use-after-free vulnerability in the Linux kernel's network namespace subsystem where a freed network structure can be accessed during cleanu...

Dec 27, 2024
CVE-2024-56640
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SMC (Shared Memory Communications) networking subsystem. It allows attackers t...

Dec 27, 2024
CVE-2024-56642
7.8

A use-after-free vulnerability in the Linux kernel's TIPC (Transparent Inter-Process Communication) subsystem allows attackers to potentially crash th...

Dec 27, 2024
CVE-2024-56631
7.8

This is a use-after-free vulnerability in the Linux kernel's SCSI generic (sg) driver that allows local attackers to potentially crash the system or e...

Dec 27, 2024
CVE-2024-56619
7.8

A memory corruption vulnerability in the Linux kernel's nilfs2 filesystem driver allows potential out-of-bounds memory access or use-after-free condit...

Dec 27, 2024
CVE-2024-56606
7.8

A use-after-free vulnerability in the Linux kernel's af_packet subsystem allows attackers to potentially execute arbitrary code or cause denial of ser...

Dec 27, 2024
CVE-2024-56600
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's IPv6 socket creation function. When inet6_create() fails during socket allocat...

Dec 27, 2024
CVE-2024-56602
7.8

A use-after-free vulnerability in the Linux kernel's IEEE 802.15.4 wireless networking subsystem allows attackers to potentially crash the kernel or e...

Dec 27, 2024
CVE-2024-56604
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's Bluetooth RFCOMM implementation. When rfcomm_dlc_alloc() fails during socket a...

Dec 27, 2024
CVE-2024-56581
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's Btrfs filesystem ref-verify feature. When an invalid reference action occurs d...

Dec 27, 2024
CVE-2024-56554
7.8

This is a use-after-free vulnerability in the Linux kernel's binder IPC subsystem. It allows local attackers to potentially crash the system or execut...

Dec 27, 2024
CVE-2024-56558
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's NFS server (nfsd) where improper reference counting during cache operations co...

Dec 27, 2024
CVE-2024-56561
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's PCI endpoint controller subsystem. When destroying a PCI endpoint controller, ...

Dec 27, 2024
CVE-2024-56551
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's AMD GPU driver (drm/amdgpu). When the driver attempts to flush a GPU scheduler...

Dec 27, 2024
CVE-2024-56538
7.8

This Linux kernel vulnerability in the ZynqMP KMS driver allows use-after-free conditions when userspace accesses a DRM device during removal. Attacke...

Dec 27, 2024
CVE-2024-56541
7.8

A use-after-free vulnerability in the Linux kernel's ath12k WiFi driver allows attackers to potentially crash the system or execute arbitrary code whe...

Dec 27, 2024
CVE-2024-53237
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's Bluetooth subsystem. When a Bluetooth device is being unregistered, a race con...

Dec 27, 2024
CVE-2024-53239
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's ALSA 6fire USB audio driver. An attacker could potentially exploit this to cau...

Dec 27, 2024
CVE-2024-53227
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's bfa SCSI driver. When bfad_im_module_init() fails during module initialization...

Dec 27, 2024
CVE-2024-53216
7.8

A use-after-free vulnerability in the Linux kernel's NFS server (nfsd) allows local attackers to potentially crash the system or execute arbitrary cod...

Dec 27, 2024
CVE-2024-53218
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's F2FS filesystem driver. Concurrent calls to f2fs_stop_gc_thread() during files...

Dec 27, 2024
CVE-2024-53206
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's TCP implementation. When a TCP connection request times out during migration, ...

Dec 27, 2024
CVE-2024-53208
7.8

This is a use-after-free vulnerability in the Linux kernel's Bluetooth management subsystem that allows reading freed memory. Attackers could potentia...

Dec 27, 2024
CVE-2024-53177
7.8

This is a use-after-free vulnerability in the Linux kernel's SMB client implementation. When open_cached_dir() encounters an error while parsing a lea...

Dec 27, 2024
CVE-2024-53179
7.8

A race condition in the Linux kernel's SMB client can cause a use-after-free vulnerability in the signing key during SMB2.1+ sign mounts. This allows ...

Dec 27, 2024
CVE-2024-53182
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's BFQ I/O scheduler. The vulnerability allows an attacker to cause memory corrup...

Dec 27, 2024
CVE-2024-53170
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's block layer that occurs when flush requests are not properly cleared from tags...

Dec 27, 2024
CVE-2024-53173
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's NFSv4.0 client implementation during asynchronous file open operations. When t...

Dec 27, 2024
CVE-2024-53165
7.8

A use-after-free vulnerability in the Linux kernel's SH architecture interrupt controller allows attackers to potentially crash the system or execute ...

Dec 27, 2024
CVE-2024-53168
7.8

This is a use-after-free vulnerability in the Linux kernel's sunrpc module affecting TCP sockets used by NFS. It allows attackers with local access to...

Dec 27, 2024
CVE-2024-12175
7.8

A use-after-free vulnerability in Rockwell Automation Arena allows arbitrary code execution when a user opens a malicious DOE file. This affects legit...

Dec 19, 2024
CVE-2022-44518
7.8

CVE-2022-44518 is a use-after-free vulnerability in Adobe Acrobat Reader DC that could allow an attacker to execute arbitrary code on a victim's syste...

Dec 19, 2024
CVE-2022-44520
7.8

CVE-2022-44520 is a use-after-free vulnerability in Adobe Acrobat Reader DC that could allow an attacker to execute arbitrary code on a victim's syste...

Dec 19, 2024
CVE-2022-44514
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malicious P...

Dec 19, 2024
CVE-2024-47040
7.8

CVE-2024-47040 is a use-after-free vulnerability in Android that allows local privilege escalation without user interaction. Attackers can exploit thi...

Dec 18, 2024
CVE-2024-49142
7.8

This vulnerability allows remote code execution through Microsoft Access when a user opens a specially crafted Access file. It affects users who open ...

Dec 12, 2024
CVE-2024-49079
7.8

This vulnerability allows attackers to execute arbitrary code remotely through Input Method Editor (IME) components. It affects systems with vulnerabl...

Dec 12, 2024
CVE-2024-49074
7.8

This vulnerability allows an authenticated attacker to exploit a use-after-free flaw in the Windows kernel-mode driver to gain SYSTEM privileges. It a...

Dec 12, 2024
CVE-2024-53953
7.8

Adobe Animate versions 23.0.8, 24.0.5 and earlier contain a use-after-free vulnerability that could allow arbitrary code execution when a user opens a...

Dec 10, 2024
CVE-2024-52997
7.8

Adobe Photoshop Desktop versions 26.0 and earlier contain a Use After Free vulnerability that could allow an attacker to execute arbitrary code on a v...

Dec 10, 2024
CVE-2024-49530
7.8

A use-after-free vulnerability in Adobe Acrobat Reader allows arbitrary code execution when a user opens a malicious PDF file. This affects multiple v...

Dec 10, 2024
CVE-2024-53143
7.8

This Linux kernel vulnerability involves a use-after-free (UAF) condition in the fsnotify subsystem due to incorrect ordering of operations when handl...

Dec 7, 2024
CVE-2024-11155
7.8

A use-after-free vulnerability in Rockwell Automation Arena allows arbitrary code execution when a user opens a malicious DOE file. This affects legit...

Dec 5, 2024
CVE-2024-53139
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SCTP IPv6 implementation. The sctp_v6_available() function accesses network de...

Dec 4, 2024
CVE-2024-53103
7.8

This CVE addresses a use-after-free vulnerability in the Linux kernel's hv_sock module where vsk->trans pointer may not be properly initialized to NUL...

Dec 2, 2024
CVE-2023-52922
7.8

This is a use-after-free vulnerability in the Linux kernel's CAN (Controller Area Network) subsystem. It allows local attackers to read freed kernel m...

Nov 28, 2024
CVE-2018-11816
7.8

CVE-2018-11816 is a use-after-free vulnerability in Android's MediaServer component that allows attackers to execute arbitrary code with elevated priv...

Nov 26, 2024
CVE-2024-9251
7.8

This CVE describes a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows information disclosure. Attackers can exploit ...

Nov 22, 2024
CVE-2024-9255
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows remote attackers to execute arbitrary code when users ope...

Nov 22, 2024
CVE-2024-7510
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp. Attackers...

Nov 22, 2024

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,308 CVEs classified as CWE-416, with 181 rated critical and 1,972 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free