CWE-416: Use After Free
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
Yearly Trend
Top Affected Vendors
All Use After Free CVEs (2,320)
This CVE is a use-after-free vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem for ARM64 architectures. When tearing do...
Jul 12, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's networking subsystem where socket creation failure leaves a dangling pointer. ...
Jul 12, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's dmaengine idxd driver. It allows an attacker to potentially execute arbitrary ...
Jul 12, 2024This is a use-after-free vulnerability in the Linux kernel's network namespace handling. It allows local attackers to trigger a kernel panic (denial o...
Jul 12, 2024A use-after-free vulnerability in the Linux kernel's cachefiles subsystem can cause a kernel hang (hung_task) when the cache is marked as dead in onde...
Jul 12, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's WWAN IOSM driver where a pointer is incorrectly handled when region creation f...
Jul 12, 2024This CVE addresses a use-after-free vulnerability in the Linux kernel's bridge Multiple Spanning Tree (MST) implementation. The flaw occurs when impro...
Jul 12, 2024A use-after-free vulnerability in the Linux kernel's xHCI driver allows attackers to cause system crashes or potentially execute arbitrary code. This ...
Jul 12, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's BPF subsystem. The flaw occurs when freeing BPF links, potentially allowing at...
Jul 12, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's cachefiles subsystem. It allows local attackers to potentially escalate privil...
Jul 12, 2024This is a use-after-free vulnerability in the Linux kernel's cachefiles subsystem that allows local attackers to potentially escalate privileges or cr...
Jul 12, 2024A use-after-free vulnerability in the Linux kernel's cachefiles subsystem allows local attackers to potentially execute arbitrary code or cause denial...
Jul 12, 2024A use-after-free vulnerability in the Linux kernel's mlx5 network driver allows local attackers to cause a kernel panic (denial of service) or potenti...
Jul 12, 2024A race condition in the Linux kernel's Greybus subsystem allows a use-after-free vulnerability when interface cleanup occurs while mode switch work is...
Jul 12, 2024This is a use-after-free vulnerability in the Linux kernel's ionic network driver where netif_napi_del() doesn't properly reset the .poll pointer, all...
Jul 12, 2024This CVE describes a use-after-free vulnerability in Android's StatsService that could allow local privilege escalation without user interaction. Atta...
Jul 9, 2024This CVE describes a use-after-free vulnerability in the RGXCreateHWRTData_aux function of rgxta3d.c that allows arbitrary code execution. It enables ...
Jul 9, 2024This vulnerability allows an attacker to gain elevated privileges on Windows systems by exploiting a use-after-free bug in the Win32k kernel driver. I...
Jul 9, 2024This is a Win32k elevation of privilege vulnerability in Windows kernel components. It allows authenticated attackers to execute arbitrary code with S...
Jul 9, 2024A use-after-free vulnerability in ASMKERN229A.dll when parsing malicious SLDPRT files in Autodesk applications could allow remote code execution. This...
Jun 25, 2024This vulnerability allows attackers to execute arbitrary code or cause crashes by tricking users into opening malicious IGES files in affected Autodes...
Jun 25, 2024A use-after-free vulnerability in Autodesk applications allows remote code execution when processing malicious CAD files (CATPART, STP, MODEL). Attack...
Jun 25, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's dmaengine idxd driver. The vulnerability occurs when file_ida is destroyed pre...
Jun 21, 2024This Linux kernel vulnerability in the vmwgfx driver allows use-after-free exploitation when a usercopy operation fails, leaving a stale file descript...
Jun 20, 2024This is a use-after-free vulnerability in the Linux kernel's rtnetlink component that could allow local attackers to crash the system or potentially e...
Jun 20, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's RDMA/ucma subsystem that occurs during concurrent multicast leave operations. ...
Jun 20, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's ALSA HD-audio subsystem. When unbinding HD-audio codec drivers, the LED class ...
Jun 20, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's RDMA subsystem. An attacker could exploit this to cause a kernel crash or pote...
Jun 19, 2024A use-after-free vulnerability in the Linux kernel's HNS3 network driver allows attackers to potentially crash the system or execute arbitrary code wi...
Jun 19, 2024A use-after-free vulnerability in the Linux kernel's CAKE (Common Applications Kept Enhanced) qdisc scheduler allows local attackers to cause denial o...
Jun 19, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's device mapper btree remove functionality. An attacker with local access could ...
Jun 19, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's GFS2 filesystem implementation. During filesystem unmount, glock objects could...
Jun 19, 2024This CVE-2024-38555 is a use-after-free vulnerability in the Linux kernel's mlx5 network driver that occurs when firmware command completions arrive w...
Jun 19, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's RDMA/hns driver where concurrent CQ asynchronous events and CQ destruction can...
Jun 19, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's bridge Multiple Spanning Tree (MST) implementation. It allows potential memory...
Jun 19, 2024CVE-2024-30089 is a use-after-free vulnerability in Microsoft Streaming Service that allows local attackers to execute arbitrary code with SYSTEM priv...
Jun 11, 2024This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by exploiting a use-after-free flaw (CWE-416) in the ...
Jun 11, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's networking subsystem where __dst_negative_advice() improperly handles RCU rule...
Jun 10, 2024A Use After Free vulnerability in Arm's Bifrost and Valhall GPU kernel drivers allows local non-privileged users to access freed memory through improp...
Jun 7, 2024A race condition vulnerability in the Linux kernel's TCP implementation allows a use-after-free condition when reusing TIME-WAIT sockets. This can lea...
May 30, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's TIPC (Transparent Inter-Process Communication) protocol implementation. When e...
May 30, 2024This is a use-after-free vulnerability in the Linux kernel's RTL8192E wireless driver. It allows attackers with local access to potentially execute ar...
May 24, 2024A use-after-free vulnerability in the Linux kernel's virtio I2C driver allows memory corruption when I2C transfers timeout. This can lead to kernel cr...
May 24, 2024A use-after-free vulnerability in the Linux kernel's mlx4_en network driver allows local attackers to potentially crash the system or execute arbitrar...
May 24, 2024This is a use-after-free vulnerability in the Linux kernel's VC4 display driver that could allow local attackers to cause kernel crashes or potentiall...
May 24, 2024This CVE describes a use-after-free and memory leak vulnerability in the Linux kernel's liteuart serial driver. When unbinding the driver, it fails to...
May 24, 2024This is a use-after-free vulnerability in the Linux kernel's CAN (Controller Area Network) subsystem affecting the pch_can driver. It allows attackers...
May 24, 2024This CVE describes a use-after-free vulnerability in the Linux kernel's ethtool subsystem. It allows local attackers to execute operations on network ...
May 24, 2024This Linux kernel vulnerability allows use-after-free attacks when using asynchronous I/O (aio) polling with signalfd or binder file descriptors. Atta...
May 24, 2024A use-after-free vulnerability in the Linux kernel's mma8452 IIO driver allows attackers to potentially crash the system or execute arbitrary code. Th...
May 24, 2024About Use After Free (CWE-416)
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
Our database tracks 2,320 CVEs classified as CWE-416, with 191 rated critical and 1,974 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.
External reference: View CWE-416 on MITRE CWE →
Monitor Use After Free Vulnerabilities
Get alerted when new Use After Free CVEs affect your infrastructure.
Start Monitoring Free