CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,320
Total CVEs
191
Critical
1,974
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 768
2 Google 389
3 Microsoft 261
4 Debian 228
5 Fedoraproject 194
6 Adobe 134
7 Foxit 84
8 Qualcomm 84
9 Apple 75
10 Mozilla 53

All Use After Free CVEs (2,320)

CVE-2024-36012
7.8

A use-after-free vulnerability in the Linux kernel's Bluetooth Microsoft extension (msft) allows local attackers to potentially crash the system or ex...

May 23, 2024
CVE-2021-47470
7.8

A use-after-free vulnerability in the Linux kernel's SLUB memory allocator debugfs interface allows local attackers to potentially execute arbitrary c...

May 22, 2024
CVE-2023-52854
7.8

A use-after-free vulnerability in the Linux kernel's padata subsystem allows local attackers to potentially crash the system or execute arbitrary code...

May 21, 2024
CVE-2023-52859
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's perf subsystem for HiSilicon uncore PMU (Performance Monitoring Unit) registra...

May 21, 2024
CVE-2023-52837
7.8

This is a use-after-free vulnerability in the Linux kernel's NBD (Network Block Device) driver that allows local attackers to potentially crash the sy...

May 21, 2024
CVE-2023-52840
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's synaptics-rmi4 touchpad driver. When exploited, it could allow local attackers...

May 21, 2024
CVE-2023-52846
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's HSR/PRP network protocol implementation. An attacker could exploit this to cau...

May 21, 2024
CVE-2023-52769
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's ath12k WiFi driver. The vulnerability occurs due to improper locking when hand...

May 21, 2024
CVE-2023-52772
7.8

This is a use-after-free vulnerability in the Linux kernel's AF_UNIX socket implementation that allows a local attacker to potentially crash the syste...

May 21, 2024
CVE-2023-52777
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's ath11k WiFi driver. The issue occurs when handling GTK (Group Temporal Key) of...

May 21, 2024
CVE-2023-52757
7.8

This CVE describes a potential deadlock vulnerability in the Linux kernel's SMB client implementation. When releasing message IDs (mids) during SMB op...

May 21, 2024
CVE-2023-52760
7.8

This is a use-after-free vulnerability in the Linux kernel's GFS2 filesystem quota handling. It allows attackers with local access to potentially cras...

May 21, 2024
CVE-2023-52741
7.8

A use-after-free vulnerability in the Linux kernel's CIFS/SMB client implementation allows attackers to potentially execute arbitrary code or cause sy...

May 21, 2024
CVE-2023-52751
7.8

This is a use-after-free vulnerability in the Linux kernel's SMB client implementation (cifs.ko). It allows attackers with access to a malicious SMB s...

May 21, 2024
CVE-2023-52707
7.8

A use-after-free vulnerability in the Linux kernel's PSI (Pressure Stall Information) subsystem allows local attackers to potentially crash the system...

May 21, 2024
CVE-2021-47427
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's iSCSI subsystem. An attacker could potentially exploit this to cause kernel me...

May 21, 2024
CVE-2021-47402
7.8

This is a use-after-free vulnerability in the Linux kernel's flower classifier (cls_flower) within the traffic control subsystem. It allows local atta...

May 21, 2024
CVE-2021-47358
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's greybus UART driver. It allows attackers to potentially execute arbitrary code...

May 21, 2024
CVE-2021-47361
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's mcb_alloc_bus() function. If exploited, it could allow local attackers to cras...

May 21, 2024
CVE-2021-47334
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's ibmasm driver module. When device initialization fails, the system attempts to...

May 21, 2024
CVE-2021-47338
7.8

This is a use-after-free vulnerability in the Linux kernel's framebuffer subsystem (fbmem). It allows attackers with local access to potentially execu...

May 21, 2024
CVE-2021-47341
7.8

This is a use-after-free vulnerability in the Linux kernel's KVM subsystem that allows a local attacker with access to the KVM ioctl interface to caus...

May 21, 2024
CVE-2021-47318
7.8

A use-after-free vulnerability in the Linux kernel's arch_topology subsystem allows race conditions when clearing scale_freq_data structures. This cou...

May 21, 2024
CVE-2021-47321
7.8

A use-after-free vulnerability in the Linux kernel watchdog driver occurs when the driver's remove function calls del_timer() without ensuring the tim...

May 21, 2024
CVE-2021-47303
7.8

A use-after-free vulnerability in the Linux kernel's BPF subsystem allows attackers to access freed memory when running BPF programs. This can lead to...

May 21, 2024
CVE-2021-47306
7.8

This is a use-after-free vulnerability in the Linux kernel's FDDI network driver that allows local attackers to potentially execute arbitrary code or ...

May 21, 2024
CVE-2021-47311
7.8

This is a use-after-free vulnerability in the Linux kernel's EMAC network driver that allows attackers to potentially execute arbitrary code or cause ...

May 21, 2024
CVE-2021-47301
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's igb network driver. When the network controller is reset while igb_poll() is r...

May 21, 2024
CVE-2021-47254
7.8

This is a use-after-free vulnerability in the Linux kernel's GFS2 filesystem implementation that could allow local attackers to cause denial of servic...

May 21, 2024
CVE-2021-47247
7.8

A use-after-free vulnerability in the Linux kernel's mlx5e network driver allows attackers to cause kernel crashes or potentially execute arbitrary co...

May 21, 2024
CVE-2024-35932
7.8

This is a use-after-free vulnerability in the Linux kernel's VC4 DRM driver that can cause kernel memory corruption and potential system crashes. It a...

May 19, 2024
CVE-2024-35921
7.8

This CVE describes a use-after-free vulnerability in the MediaTek video codec driver for the Linux kernel. When HEVC decoder initialization fails, the...

May 19, 2024
CVE-2024-35866
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SMB client implementation. Attackers could potentially exploit this to crash t...

May 19, 2024
CVE-2024-35868
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SMB client implementation. An attacker could potentially exploit this to crash...

May 19, 2024
CVE-2024-35861
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SMB client implementation. Attackers could potentially exploit this to crash t...

May 19, 2024
CVE-2024-35863
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SMB client implementation. An attacker could potentially exploit this to crash...

May 19, 2024
CVE-2024-35789
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's WiFi subsystem (mac80211). When a station is moved out of a VLAN and the VLAN ...

May 17, 2024
CVE-2024-35791
7.8

This is a use-after-free vulnerability in the Linux kernel's KVM SVM (Secure Virtual Machine) subsystem. It allows a malicious user with access to a K...

May 17, 2024
CVE-2024-30275
7.8

Adobe Aero Desktop versions 23.4 and earlier contain a Use After Free vulnerability (CWE-416) that could allow arbitrary code execution when a user op...

May 16, 2024
CVE-2024-20792
7.8

This CVE describes a Use After Free vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious file. T...

May 16, 2024
CVE-2024-34100
7.8

CVE-2024-34100 is a use-after-free vulnerability in Adobe Acrobat Reader that could allow attackers to execute arbitrary code when a user opens a mali...

May 15, 2024
CVE-2024-34096
7.8

Adobe Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier contain a use-after-free vulnerability that could allow arbitrary code execution ...

May 15, 2024
CVE-2024-34094
7.8

CVE-2024-34094 is a use-after-free vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious PDF f...

May 15, 2024
CVE-2024-30049
7.8

This Windows kernel vulnerability allows attackers to gain elevated system privileges by exploiting a use-after-free condition in the Win32k subsystem...

May 14, 2024
CVE-2024-30035
7.8

This vulnerability in the Windows Desktop Window Manager (DWM) Core Library allows an authenticated attacker to execute arbitrary code with SYSTEM pri...

May 14, 2024
CVE-2024-30031
7.8

This vulnerability in the Windows CNG Key Isolation Service allows an authenticated attacker to gain SYSTEM-level privileges by exploiting a use-after...

May 14, 2024
CVE-2024-27398
7.8

This is a use-after-free vulnerability in the Linux kernel's Bluetooth subsystem where a scheduled timeout worker thread can access a socket object af...

May 14, 2024
CVE-2024-27396
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's GTP (GPRS Tunneling Protocol) implementation. Attackers could potentially expl...

May 14, 2024
CVE-2023-40490
7.8

This is a use-after-free vulnerability in Maxon Cinema 4D's SKP file parser that allows remote code execution. Attackers can exploit it by tricking us...

May 7, 2024
CVE-2022-43651
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected Bentley View installations by tricking users into opening malicious S...

May 7, 2024

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,320 CVEs classified as CWE-416, with 191 rated critical and 1,974 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free