CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,201
Total CVEs
154
Critical
1,892
High
7.9
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 762
2 Google 348
3 Microsoft 258
4 Debian 190
5 Fedoraproject 167
6 Adobe 122
7 Foxit 84
8 Qualcomm 78
9 Apple 62
10 Mozilla 47

All Use After Free CVEs (2,201)

CVE-2020-35902
9.8

This vulnerability in the actix-codec crate for Rust allows attackers to exploit a use-after-free memory corruption flaw in the Framed component. This...

Dec 31, 2020
CVE-2020-28951
9.8

CVE-2020-28951 is a use-after-free vulnerability in libuci (Unified Configuration Interface) used by OpenWrt. Attackers can exploit this by providing ...

Nov 19, 2020
CVE-2020-1909
9.8

A use-after-free vulnerability in WhatsApp's iOS logging library could allow memory corruption, crashes, or potentially remote code execution. This af...

Nov 3, 2020
CVE-2020-15993
9.8

This is a use-after-free vulnerability in Chrome's printing component that allows remote attackers to potentially exploit heap corruption. Attackers c...

Nov 3, 2020
CVE-2019-8578
9.8

CVE-2019-8578 is a use-after-free vulnerability in Apple AirPort Base Station firmware that allows remote attackers to execute arbitrary code on affec...

Oct 27, 2020
CVE-2020-15683
9.8

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could exploit...

Oct 22, 2020
CVE-2020-3992
9.8

This vulnerability allows a malicious actor on the management network to exploit a use-after-free flaw in OpenSLP service on VMware ESXi, potentially ...

Oct 20, 2020
CVE-2020-9895
9.8

This is a critical use-after-free memory corruption vulnerability in Apple's iOS, iPadOS, tvOS, watchOS, Safari, iTunes, and iCloud for Windows. A rem...

Oct 16, 2020
CVE-2020-26534
9.8

This CVE describes a use-after-free vulnerability in Foxit Reader and PhantomPDF's AcroForm JavaScript engine. Attackers can exploit this by crafting ...

Oct 2, 2020
CVE-2020-26539
9.8

This vulnerability in Foxit Reader and PhantomPDF allows attackers to execute arbitrary code on affected systems by exploiting a use-after-free memory...

Oct 2, 2020
CVE-2020-0252
9.8

CVE-2020-0252 is a use-after-free vulnerability in Android System-on-Chip (SoC) components that could allow memory corruption. If exploited, it could ...

Aug 11, 2020
CVE-2024-4671
9.6

This is a use-after-free vulnerability in Google Chrome's Visuals component that allows a remote attacker who has already compromised the renderer pro...

May 14, 2024
CVE-2024-4558
9.6

This is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. It allows remote attackers to potent...

May 7, 2024
CVE-2023-50716
9.6

CVE-2023-50716 is a use-after-free vulnerability in eProsima Fast DDS that allows remote attackers to crash the Fast-DDS process by sending specially ...

Mar 6, 2024
CVE-2024-21326
9.6

This vulnerability in Microsoft Edge allows attackers to gain elevated privileges on affected systems by exploiting a use-after-free memory corruption...

Jan 26, 2024
CVE-2023-36735
9.6

This vulnerability in Microsoft Edge allows attackers to execute arbitrary code with elevated privileges by exploiting a use-after-free memory corrupt...

Sep 15, 2023
CVE-2022-4924
9.6

This is a use-after-free vulnerability in Chrome's WebRTC component that allows an attacker who has already compromised the renderer process to escape...

Jul 29, 2023
CVE-2022-1312
9.6

This is a use-after-free vulnerability in Chrome's storage component that allows an attacker who convinces a user to install a malicious extension to ...

Jul 25, 2022
CVE-2022-0977
9.6

This is a use-after-free vulnerability in Chrome's Browser UI on Chrome OS that allows remote attackers to potentially exploit heap corruption. Attack...

Jul 21, 2022
CVE-2022-0973
9.6

This is a use-after-free vulnerability in Google Chrome's Safe Browsing feature that allows remote attackers to potentially exploit heap corruption. A...

Jul 21, 2022
CVE-2022-0790
9.6

This is a use-after-free vulnerability in Chrome's Cast UI that allows sandbox escape. An attacker could exploit it by tricking a user into interactin...

Apr 5, 2022
CVE-2022-0452
9.6

A use-after-free vulnerability in Chrome's Safe Browsing component allows remote attackers to potentially escape the browser sandbox via a crafted HTM...

Apr 5, 2022
CVE-2022-0290
9.6

This is a use-after-free vulnerability in Chrome's site isolation feature that allows a remote attacker to escape the browser sandbox via a malicious ...

Feb 12, 2022
CVE-2021-38002
9.6

This is a use-after-free vulnerability in Chrome's Web Transport component that allows a remote attacker to potentially escape the browser sandbox via...

Nov 23, 2021
CVE-2020-6492
9.6

This is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome that could allow a remote attacker to...

Nov 2, 2021
CVE-2021-37973
9.6

This is a use-after-free vulnerability in Google Chrome's Portals feature that allows a remote attacker who has already compromised the renderer proce...

Oct 8, 2021
CVE-2021-30633
9.6

This is a use-after-free vulnerability in Chrome's IndexedDB API that allows an attacker who has already compromised the renderer process to escape th...

Oct 8, 2021
CVE-2021-21201
9.6

This is a use-after-free vulnerability in Google Chrome's permissions system that allows an attacker who has already compromised the renderer process ...

Apr 26, 2021
CVE-2021-21226
9.6

This is a use-after-free vulnerability in Google Chrome's navigation component that allows a compromised renderer process to escape the browser sandbo...

Apr 26, 2021
CVE-2021-21150
9.6

This is a use-after-free vulnerability in Google Chrome's Downloads component on Windows that allows a remote attacker who has already compromised the...

Feb 22, 2021
CVE-2021-21142
9.6

This is a use-after-free vulnerability in Google Chrome's Payments component on macOS that could allow a remote attacker to escape the browser sandbox...

Feb 9, 2021
CVE-2021-21146
9.6

This is a use-after-free vulnerability in Google Chrome's navigation component that allows a remote attacker who has already compromised the renderer ...

Feb 9, 2021
CVE-2021-21121
9.6

This is a use-after-free vulnerability in the Omnibox (address bar) component of Google Chrome on Linux. It allows a remote attacker to potentially es...

Feb 9, 2021
CVE-2021-21124
9.6

This is a use-after-free vulnerability in Google Chrome's Speech Recognizer component on Android. It allows a remote attacker to potentially escape Ch...

Feb 9, 2021
CVE-2020-16045
9.6

This is a use-after-free vulnerability in Google Chrome's Payments component on Android that allows a remote attacker who has already compromised the ...

Jan 14, 2021
CVE-2021-21110
9.6

This is a use-after-free vulnerability in Google Chrome's safe browsing component that allows a remote attacker to potentially escape the browser sand...

Jan 8, 2021
CVE-2021-21115
9.6

This is a use-after-free vulnerability in Chrome's safe browsing component that allows a compromised renderer process to escape the browser sandbox. A...

Jan 8, 2021
CVE-2021-21106
9.6

This is a use-after-free vulnerability in Chrome's autofill feature that allows an attacker who has already compromised the renderer process to escape...

Jan 8, 2021
CVE-2021-21108
9.6

This is a critical use-after-free vulnerability in Google Chrome's media component that allows a remote attacker who has already compromised the rende...

Jan 8, 2021
CVE-2020-16014
9.6

This is a use-after-free vulnerability in Chrome's Pepper Plugin API (PPAPI) that allows an attacker who has already compromised the renderer process ...

Jan 8, 2021
CVE-2020-16018
9.6

This is a use-after-free vulnerability in Google Chrome's payments component that allows a remote attacker who has already compromised the renderer pr...

Jan 8, 2021
CVE-2020-6573
9.6

This is a use-after-free vulnerability in Google Chrome's video component on Android that allows a remote attacker who has already compromised the ren...

Sep 21, 2020
CVE-2024-22267
9.3

CVE-2024-22267 is a use-after-free vulnerability in VMware Workstation and Fusion's vbluetooth device that allows a malicious actor with local adminis...

May 14, 2024
CVE-2024-22252
9.3

This CVE describes a use-after-free vulnerability in VMware's XHCI USB controller that allows a malicious actor with local administrative privileges o...

Mar 5, 2024
CVE-2024-47834
9.1

A use-after-free vulnerability in GStreamer's Matroska demuxer allows reading freed memory when processing CodecPrivate elements. This can lead to cra...

Dec 12, 2024
CVE-2024-38920
9.1

CVE-2024-38920 is a use-after-free vulnerability in ROS2 Nav2's AMCL component that allows remote attackers to potentially execute arbitrary code or c...

Dec 5, 2024
CVE-2024-38159
9.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems with Network Virtualization enabled by exploiting a use-after-...

Aug 13, 2024
CVE-2024-25198
9.1

This CVE describes a use-after-free vulnerability in ROS2 Nav2's AMCL node due to incorrect pointer reset order. Attackers could exploit this to crash...

Feb 20, 2024
CVE-2022-22260
9.1

This CVE-2022-22260 is a use-after-free vulnerability in a kernel module that could allow attackers to corrupt memory. Successful exploitation could l...

May 13, 2022
CVE-2022-1106
9.1

CVE-2022-1106 is a use-after-free vulnerability in mrb_vm_exec in mruby, a lightweight Ruby implementation. This vulnerability allows attackers to exe...

Mar 27, 2022

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,201 CVEs classified as CWE-416, with 154 rated critical and 1,892 rated high severity. The average CVSS score for Use After Free vulnerabilities is 7.9.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free