CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,320
Total CVEs
191
Critical
1,974
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 768
2 Google 389
3 Microsoft 261
4 Debian 228
5 Fedoraproject 194
6 Adobe 134
7 Foxit 84
8 Qualcomm 84
9 Apple 75
10 Mozilla 53

All Use After Free CVEs (2,320)

CVE-2021-34974
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows remote attackers to execute arbitrary code when a user op...

May 7, 2024
CVE-2021-34966
7.8

This is a use-after-free vulnerability in Foxit PDF Editor's handling of FileAttachment annotations that allows remote code execution. Attackers can e...

May 7, 2024
CVE-2021-34968
7.8

This is a use-after-free vulnerability in Foxit PDF Editor's transitionToState method that allows remote attackers to execute arbitrary code. Attacker...

May 7, 2024
CVE-2021-34960
7.8

This is a use-after-free vulnerability in Foxit PDF Editor's handling of Circle Annotation objects, allowing remote attackers to execute arbitrary cod...

May 7, 2024
CVE-2021-34962
7.8

This is a use-after-free vulnerability in Foxit PDF Editor's handling of Caret Annotation objects that allows remote code execution. Attackers can exp...

May 7, 2024
CVE-2021-34964
7.8

This is a use-after-free vulnerability in Foxit PDF Editor's polygon annotation handling that allows remote code execution when users open malicious P...

May 7, 2024
CVE-2021-34954
7.8

This is a use-after-free vulnerability in Foxit PDF Editor's handling of StrikeOut annotations that allows remote code execution. Attackers can exploi...

May 7, 2024
CVE-2021-34956
7.8

This is a use-after-free vulnerability in Foxit PDF Editor's underline annotation handling that allows remote attackers to execute arbitrary code. Use...

May 7, 2024
CVE-2021-34958
7.8

This is a use-after-free vulnerability in Foxit PDF Editor's text annotation handling that allows remote attackers to execute arbitrary code when a us...

May 7, 2024
CVE-2021-34952
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by exploiting a use-after-free flaw in Annotation object hand...

May 7, 2024
CVE-2022-48695
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's mpt3sas SCSI driver that occurs during controller reset operations. Attackers ...

May 3, 2024
CVE-2022-48670
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's PECI (Platform Environment Control Interface) CPU driver. When auxiliary_devic...

May 3, 2024
CVE-2022-48674
7.8

This is a use-after-free vulnerability in the Linux kernel's EROFS filesystem implementation that occurs specifically on UP (Uniprocessor) platforms. ...

May 3, 2024
CVE-2022-48686
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's NVMe over TCP implementation. When digest errors are detected during NVMe over...

May 3, 2024
CVE-2023-51563
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious XPS files in Kofax Power PDF. The flaw i...

May 3, 2024
CVE-2023-51565
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious XPS files in Kofax Power PDF. The flaw i...

May 3, 2024
CVE-2023-51556
7.8

This vulnerability in Foxit PDF Reader allows attackers to execute arbitrary code by tricking users into opening malicious PDF files. It affects users...

May 3, 2024
CVE-2023-51551
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's AcroForm signature handling that allows remote code execution. Attackers can exploit it b...

May 3, 2024
CVE-2023-50196
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp Viewer. Th...

May 3, 2024
CVE-2023-50192
7.8

This is a use-after-free vulnerability in Trimble SketchUp Viewer's SKP file parser that allows remote attackers to execute arbitrary code. Attackers ...

May 3, 2024
CVE-2023-44435
7.8

This is a use-after-free vulnerability in Kofax Power PDF's file parsing that allows remote attackers to execute arbitrary code when a user opens a ma...

May 3, 2024
CVE-2023-42108
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious EMF files. The fla...

May 3, 2024
CVE-2023-42103
7.8

This is a use-after-free vulnerability in Ashlar-Vellum Cobalt's AR file parser that allows remote code execution. Attackers can exploit it by trickin...

May 3, 2024
CVE-2023-42092
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's Doc object handling that allows remote attackers to execute arbitrary code. Attackers can...

May 3, 2024
CVE-2023-42094
7.8

This CVE describes a use-after-free vulnerability in Foxit PDF Reader's annotation handling, allowing remote attackers to execute arbitrary code by tr...

May 3, 2024
CVE-2023-42096
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's PDF file parsing that allows remote attackers to execute arbitrary code when a user opens...

May 3, 2024
CVE-2023-42080
7.8

This is a use-after-free vulnerability in PDF-XChange Editor's EMF file parser that allows remote attackers to execute arbitrary code when a user open...

May 3, 2024
CVE-2023-42082
7.8

PDF-XChange Editor contains a use-after-free vulnerability in JPG file parsing that allows remote code execution when users open malicious files or vi...

May 3, 2024
CVE-2023-42059
7.8

This is a use-after-free vulnerability in PDF-XChange Editor's U3D file parser that allows remote attackers to execute arbitrary code when users open ...

May 3, 2024
CVE-2023-42040
7.8

A use-after-free vulnerability in PDF-XChange Editor's mailForm method allows remote attackers to execute arbitrary code when users open malicious PDF...

May 3, 2024
CVE-2023-40487
7.8

This is a use-after-free vulnerability in Maxon Cinema 4D's SKP file parser that allows remote code execution when a user opens a malicious SKP file o...

May 3, 2024
CVE-2023-40489
7.8

A use-after-free vulnerability in Maxon Cinema 4D's SKP file parser allows remote attackers to execute arbitrary code when users open malicious SKP fi...

May 3, 2024
CVE-2023-39488
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

May 3, 2024
CVE-2023-38114
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's AcroForm Doc object handling that allows remote attackers to execute arbitrary code when ...

May 3, 2024
CVE-2023-38117
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's AcroForm Doc object handling that allows remote attackers to execute arbitrary code. Atta...

May 3, 2024
CVE-2023-38107
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows remote attackers to execute arbitrary code when a user op...

May 3, 2024
CVE-2023-38111
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows remote attackers to execute arbitrary code when a user op...

May 3, 2024
CVE-2023-27366
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's Doc object handling that allows remote attackers to execute arbitrary code. Attackers can...

May 3, 2024
CVE-2023-27330
7.8

This is a use-after-free vulnerability in Foxit PDF Reader's XFA annotation handling that allows remote code execution. Attackers can exploit it by tr...

May 3, 2024
CVE-2024-30305
7.8

CVE-2024-30305 is a use-after-free vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious PDF f...

May 2, 2024
CVE-2024-30303
7.8

CVE-2024-30303 is a use-after-free vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious PDF f...

May 2, 2024
CVE-2024-27070
7.8

This is a use-after-free vulnerability in the Linux kernel's F2FS filesystem driver that occurs during memory page fault handling. When exploited, it ...

May 1, 2024
CVE-2024-27061
7.8

This is a use-after-free vulnerability in the Linux kernel's sun8i-ce cryptographic driver that can cause kernel crashes or potential privilege escala...

May 1, 2024
CVE-2024-26944
7.8

This is a use-after-free vulnerability in the Linux kernel's Btrfs filesystem zoned mode implementation. It allows an attacker with local access to po...

May 1, 2024
CVE-2022-48637
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's bnxt network driver. When handling PTP timestamping, the driver incorrectly re...

Apr 28, 2024
CVE-2024-31583
7.8

PyTorch versions before v2.2.0 contain a use-after-free vulnerability in the mobile interpreter component. This allows attackers to potentially execut...

Apr 17, 2024
CVE-2024-26907
7.8

This CVE-2024-26907 is a use-after-free vulnerability in the Linux kernel's RDMA/mlx5 driver that occurs when accessing Ethernet segments. It allows l...

Apr 17, 2024
CVE-2024-26892
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's mt7921e WiFi driver. When removing the driver module (rmmod), the system attem...

Apr 17, 2024
CVE-2024-26895
7.8

This is a use-after-free vulnerability in the Linux kernel's wilc1000 WiFi driver that occurs during network interface cleanup. When removing WiFi int...

Apr 17, 2024
CVE-2024-26898
7.8

This vulnerability in the Linux kernel's ATA over Ethernet (AoE) driver allows a use-after-free condition in the aoecmd_cfg_pkts function. Attackers c...

Apr 17, 2024

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,320 CVEs classified as CWE-416, with 191 rated critical and 1,974 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free