CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,308
Total CVEs
181
Critical
1,972
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 767
2 Google 387
3 Microsoft 259
4 Debian 227
5 Fedoraproject 194
6 Adobe 131
7 Foxit 84
8 Qualcomm 83
9 Apple 75
10 Mozilla 53

All Use After Free CVEs (2,308)

CVE-2024-9764
7.8

A use-after-free vulnerability in Tungsten Automation Power PDF allows remote attackers to execute arbitrary code when users open malicious PDF files....

Nov 22, 2024
CVE-2024-9729
7.8

This is a use-after-free vulnerability in Trimble SketchUp Viewer's SKP file parser that allows remote code execution. Attackers can exploit it by tri...

Nov 22, 2024
CVE-2024-9719
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected Trimble SketchUp Viewer installations by tricking users into opening ...

Nov 22, 2024
CVE-2024-9721
7.8

A use-after-free vulnerability in Trimble SketchUp Viewer's SKP file parsing allows remote attackers to execute arbitrary code when a user opens a mal...

Nov 22, 2024
CVE-2024-9723
7.8

This is a use-after-free vulnerability in Trimble SketchUp Viewer's SKP file parser that allows remote attackers to execute arbitrary code. Attackers ...

Nov 22, 2024
CVE-2024-9725
7.8

This is a use-after-free vulnerability in Trimble SketchUp Viewer's SKP file parser that allows remote attackers to execute arbitrary code. Attackers ...

Nov 22, 2024
CVE-2024-9727
7.8

This is a use-after-free vulnerability in Trimble SketchUp Viewer's SKP file parser that allows remote code execution. Attackers can exploit it by tri...

Nov 22, 2024
CVE-2024-9713
7.8

A use-after-free vulnerability in Trimble SketchUp Pro's SKP file parser allows remote attackers to execute arbitrary code when a user opens a malicio...

Nov 22, 2024
CVE-2024-9715
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Trimble SketchUp Viewer. Attackers can ...

Nov 22, 2024
CVE-2024-11545
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. The flaw is a us...

Nov 22, 2024
CVE-2024-11521
7.8

This is a use-after-free vulnerability in IrfanView's DJVU file parser that allows remote code execution. Attackers can exploit it by tricking users i...

Nov 22, 2024
CVE-2024-11525
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView. Attackers can exploit this b...

Nov 22, 2024
CVE-2024-53095
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's CIFS/SMB client where network namespace references are incorrectly managed. It...

Nov 21, 2024
CVE-2018-9417
7.8

This vulnerability allows local attackers to escalate privileges on Android devices through a use-after-free bug in the USB HID gadget driver. It affe...

Nov 19, 2024
CVE-2024-53068
7.8

This is a use-after-free vulnerability in the Linux kernel's SCMI (System Control and Management Interface) subsystem where scmi_dev->name is freed pr...

Nov 19, 2024
CVE-2024-53057
7.8

A use-after-free vulnerability in the Linux kernel's traffic control subsystem allows local attackers to potentially crash the system or execute arbit...

Nov 19, 2024
CVE-2024-50293
7.8

A use-after-free vulnerability in the Linux kernel's SMC (Shared Memory Communications) implementation allows local attackers to potentially escalate ...

Nov 19, 2024
CVE-2024-50280
7.8

This vulnerability in the Linux kernel's dm-cache subsystem causes a kernel warning when cache creation fails, due to improper cleanup of uninitialize...

Nov 19, 2024
CVE-2024-50274
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's idpf driver. When monitoring tools query network link settings during a driver...

Nov 19, 2024
CVE-2024-50267
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's USB serial io_edgeport driver. An attacker could potentially exploit this to c...

Nov 19, 2024
CVE-2024-50269
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's USB MUSB driver for Sunxi platforms. When the USB PHY is accessed after being ...

Nov 19, 2024
CVE-2023-52921
7.8

A use-after-free vulnerability in the AMD GPU driver for Linux kernel allows local attackers to potentially crash the system or execute arbitrary code...

Nov 19, 2024
CVE-2024-34747
7.8

CVE-2024-34747 is a use-after-free vulnerability in Android's devicemem_server.c that allows local attackers to escalate privileges in the kernel with...

Nov 13, 2024
CVE-2024-49021
7.8

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SQL Server instances by exploiting a use-after-free memory corruptio...

Nov 12, 2024
CVE-2024-49027
7.8

This vulnerability allows attackers to execute arbitrary code on systems running vulnerable versions of Microsoft Excel by tricking users into opening...

Nov 12, 2024
CVE-2024-50257
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's netfilter subsystem, specifically in the ip6table_nat module. It allows local ...

Nov 9, 2024
CVE-2024-50261
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's MACsec implementation. When MACsec offloading is enabled, the kernel can attem...

Nov 9, 2024
CVE-2024-50226
7.8

A use-after-free vulnerability in the Linux kernel's CXL (Compute Express Link) subsystem allows local attackers to cause a kernel crash or potentiall...

Nov 9, 2024
CVE-2024-50217
7.8

A use-after-free vulnerability in the Linux kernel's btrfs filesystem allows an attacker to potentially crash the system or execute arbitrary code. Th...

Nov 9, 2024
CVE-2024-50186
7.8

This CVE-2024-50186 is a use-after-free vulnerability in the Linux kernel's network subsystem where socket creation failures can leave dangling sk poi...

Nov 8, 2024
CVE-2024-50150
7.8

This is a use-after-free vulnerability in the Linux kernel's USB Type-C alternate mode subsystem. When an altmode device is released, it references it...

Nov 7, 2024
CVE-2024-50121
7.8

A race condition vulnerability in the Linux kernel's NFS server (nfsd) can cause use-after-free errors and kernel warnings when shutting down NFS serv...

Nov 5, 2024
CVE-2024-50125
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's Bluetooth SCO (Synchronous Connection-Oriented) subsystem. An attacker could p...

Nov 5, 2024
CVE-2024-50127
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's network scheduler (taprio_change() function). Attackers could potentially expl...

Nov 5, 2024
CVE-2024-50114
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem for ARM64. When vCPU creation fai...

Nov 5, 2024
CVE-2024-38415
7.8

This CVE describes a use-after-free vulnerability (CWE-416) in Qualcomm firmware that occurs when handling session errors. An attacker could exploit t...

Nov 4, 2024
CVE-2024-38421
7.8

This vulnerability allows memory corruption while processing GPU commands in Qualcomm hardware, potentially enabling attackers to execute arbitrary co...

Nov 4, 2024
CVE-2024-8590
7.8

This CVE describes a use-after-free vulnerability in Autodesk AutoCAD's 3DM file parser. Attackers can exploit this by tricking users into opening mal...

Oct 29, 2024
CVE-2024-50073
7.8

A use-after-free vulnerability in the Linux kernel's GSM multiplexer (n_gsm) allows attackers to potentially execute arbitrary code or cause denial of...

Oct 29, 2024
CVE-2024-44285
7.8

This CVE describes a use-after-free vulnerability in Apple's iOS, iPadOS, watchOS, visionOS, and tvOS kernels that could allow a malicious app to caus...

Oct 28, 2024
CVE-2024-48423
7.8

A use-after-free vulnerability in assimp v5.4.3 allows local attackers to execute arbitrary code via the CallbackToLogRedirector function. This affect...

Oct 24, 2024
CVE-2024-50047
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SMB client when performing asynchronous decryption of large files. The vulnera...

Oct 21, 2024
CVE-2024-50029
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's Bluetooth subsystem. An attacker could potentially exploit this to crash the k...

Oct 21, 2024
CVE-2022-49025
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's mlx5e network driver. When multiple destination termination tables fail during...

Oct 21, 2024
CVE-2022-49029
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's IBM Power Executive (ibmpex) hardware monitoring driver. When ibmpex_register_...

Oct 21, 2024
CVE-2022-49006
7.8

This is a use-after-free vulnerability in the Linux kernel's tracing subsystem where dynamic events (like kprobes) can have their type numbers reused ...

Oct 21, 2024
CVE-2022-49014
7.8

This is a use-after-free vulnerability in the Linux kernel's TUN/TAP network driver that occurs during device detachment. When exploited, it can cause...

Oct 21, 2024
CVE-2022-49017
7.8

This is a use-after-free vulnerability in the Linux kernel's TIPC (Transparent Inter-Process Communication) subsystem. An attacker could potentially c...

Oct 21, 2024
CVE-2022-48990
7.8

This CVE describes a use-after-free vulnerability in the AMD GPU driver within the Linux kernel. An attacker could potentially exploit this during GPU...

Oct 21, 2024
CVE-2022-48962
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's hisilicon network driver. If exploited, it could allow local attackers to cras...

Oct 21, 2024

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,308 CVEs classified as CWE-416, with 181 rated critical and 1,972 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free