CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,336
Total CVEs
195
Critical
1,985
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
105
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 769
2 Google 393
3 Microsoft 261
4 Debian 232
5 Fedoraproject 197
6 Adobe 140
7 Qualcomm 85
8 Foxit 84
9 Apple 75
10 Mozilla 53

All Use After Free CVEs (2,336)

CVE-2021-47103
7.8

This is a use-after-free vulnerability in the Linux kernel's networking subsystem where improper RCU (Read-Copy-Update) handling of socket destination...

Mar 4, 2024
CVE-2024-26622
7.8

A use-after-free vulnerability in the Linux kernel's TOMOYO security module allows attackers with write access to the TOMOYO control interface to caus...

Mar 4, 2024
CVE-2023-52530
7.8

This vulnerability in the Linux kernel's WiFi subsystem (mac80211) could allow use-after-free of cryptographic keys when handling GTK rekey operations...

Mar 2, 2024
CVE-2023-52509
7.8

This is a use-after-free vulnerability in the Linux kernel's RAVB Ethernet driver that could allow local attackers to crash the system or potentially ...

Mar 2, 2024
CVE-2023-52515
7.8

This is a use-after-free vulnerability in the Linux kernel's RDMA/srp subsystem. When the SCSI abort handler is called, improper cleanup can trigger m...

Mar 2, 2024
CVE-2021-47081
7.8

This is a use-after-free vulnerability in the Linux kernel's Habana Labs Gaudi AI accelerator driver. It could allow local attackers to cause kernel m...

Mar 1, 2024
CVE-2021-47068
7.8

This is a use-after-free vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem. It allows local attackers to potentially crash ...

Feb 29, 2024
CVE-2021-46959
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SPI subsystem. When using devm_spi_alloc_* functions, improper cleanup during ...

Feb 29, 2024
CVE-2021-47058
7.8

This is a use-after-free vulnerability in the Linux kernel's regmap subsystem where debugfs_name is freed but not set to NULL, potentially causing mem...

Feb 29, 2024
CVE-2021-47061
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem. When unregistering an I/O bus de...

Feb 29, 2024
CVE-2021-47063
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's DRM (Direct Rendering Manager) subsystem. When a bridge is detached from a pan...

Feb 29, 2024
CVE-2024-20765
7.8

A use-after-free vulnerability in Adobe Acrobat Reader allows arbitrary code execution when a user opens a malicious PDF file. This affects users runn...

Feb 29, 2024
CVE-2021-47048
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SPI driver for ZynqMP GQSPI controllers. An attacker could exploit this to cau...

Feb 28, 2024
CVE-2021-46969
7.8

A use-after-free vulnerability in the Linux kernel's MHI bus subsystem could allow local attackers to cause memory corruption or system crashes. The v...

Feb 27, 2024
CVE-2021-46936
7.8

This is a use-after-free vulnerability in the Linux kernel's networking subsystem that can cause kernel panic and system crashes. It affects Linux sys...

Feb 27, 2024
CVE-2019-25162
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's I2C subsystem. An attacker could potentially exploit this to cause a kernel cr...

Feb 26, 2024
CVE-2023-52468
7.8

A use-after-free vulnerability in the Linux kernel's class_register() function allows attackers to potentially execute arbitrary code or cause system ...

Feb 26, 2024
CVE-2022-48626
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's moxart MMC host driver. An attacker with local access could potentially exploi...

Feb 26, 2024
CVE-2023-52457
7.8

This vulnerability in the Linux kernel's 8250 serial driver for OMAP platforms causes a use-after-free condition when device removal fails. It allows ...

Feb 23, 2024
CVE-2024-26592
7.8

This is a use-after-free vulnerability in the Linux kernel's ksmbd SMB server module that allows attackers to potentially crash the kernel or execute ...

Feb 22, 2024
CVE-2023-52446
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's BPF subsystem where a race condition between btf_put() and map_free() operatio...

Feb 22, 2024
CVE-2023-52438
7.8

This is a use-after-free vulnerability in the Linux kernel's binder driver that occurs during memory shrinker operations. It allows attackers to poten...

Feb 20, 2024
CVE-2023-21165
7.8

This vulnerability allows local attackers to execute arbitrary code in the Android kernel through a use-after-free bug in the device memory management...

Feb 16, 2024
CVE-2023-40114
7.8

This vulnerability in Android's Media Transfer Protocol (MTP) implementation allows local privilege escalation through a use-after-free condition in M...

Feb 15, 2024
CVE-2023-40100
7.8

This vulnerability allows local privilege escalation on Android devices due to memory corruption in DNS64 configuration handling. It affects Android s...

Feb 15, 2024
CVE-2024-21384
7.8

This vulnerability allows remote code execution through specially crafted OneNote files. Attackers can exploit this by tricking users into opening mal...

Feb 13, 2024
CVE-2024-1085
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's netfilter nf_tables component that allows local privilege escalation. An attac...

Jan 31, 2024
CVE-2024-22915
7.8

A heap-use-after-free vulnerability in SWFTools v0.9.2 allows attackers to execute arbitrary code by exploiting improper memory handling in the swf_De...

Jan 19, 2024
CVE-2024-22920
7.8

CVE-2024-22920 is a heap-use-after-free vulnerability in swftools 0.9.2 that allows attackers to execute arbitrary code or cause denial of service. Th...

Jan 19, 2024
CVE-2024-0562
7.8

A use-after-free vulnerability in the Linux kernel's writeback subsystem allows attackers to potentially crash the system or execute arbitrary code wi...

Jan 15, 2024
CVE-2023-42870
7.8

This CVE describes a use-after-free vulnerability in Apple operating systems that allows an app to execute arbitrary code with kernel privileges. It a...

Jan 10, 2024
CVE-2024-20681
7.8

This vulnerability allows attackers to elevate privileges within the Windows Subsystem for Linux (WSL) environment. An authenticated attacker could ex...

Jan 9, 2024
CVE-2024-20683
7.8

This CVE describes a Win32k elevation of privilege vulnerability in Windows kernel components. It allows authenticated attackers to gain SYSTEM-level ...

Jan 9, 2024
CVE-2023-37576
7.8

CVE-2023-37576 is a use-after-free vulnerability in GTKWave's VCD file parser that allows arbitrary code execution when a malicious .vcd file is opene...

Jan 8, 2024
CVE-2023-37578
7.8

CVE-2023-37578 is a use-after-free vulnerability in GTKWave's VCD file parser that allows arbitrary code execution when a malicious .vcd file is opene...

Jan 8, 2024
CVE-2023-37574
7.8

This vulnerability allows arbitrary code execution when a user opens a specially crafted .vcd file in GTKWave. Attackers can exploit use-after-free fl...

Jan 8, 2024
CVE-2024-0193
7.8

A use-after-free vulnerability in the Linux kernel's netfilter subsystem allows local unprivileged users with CAP_NET_ADMIN capability to escalate pri...

Jan 2, 2024
CVE-2023-33118
7.8

This CVE describes a use-after-free vulnerability in Qualcomm's Sound Technology Hardware Abstraction Layer (ST HAL) when processing Listen Sound Mode...

Jan 2, 2024
CVE-2023-6932
7.8

This CVE-2023-6932 is a use-after-free vulnerability in the Linux kernel's IGMP (Internet Group Management Protocol) component that allows local attac...

Dec 19, 2023
CVE-2023-6817
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's netfilter nf_tables component. It allows local attackers to escalate privilege...

Dec 18, 2023
CVE-2022-22942
7.8

CVE-2022-22942 is a local privilege escalation vulnerability in the vmwgfx driver that allows unprivileged local users to access files opened by other...

Dec 13, 2023
CVE-2023-40084
7.8

This CVE describes a use-after-free vulnerability in Android's mDNS service discovery component (MDnsSdListener.cpp) that allows local privilege escal...

Dec 4, 2023
CVE-2023-44372
7.8

This CVE describes a Use After Free vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious PDF ...

Nov 16, 2023
CVE-2023-44367
7.8

This CVE describes a Use After Free vulnerability in Adobe Acrobat Reader that could allow an attacker to execute arbitrary code on a victim's system....

Nov 16, 2023
CVE-2023-44359
7.8

Adobe Acrobat Reader versions 23.006.20360 and earlier, and 20.005.30524 and earlier, contain a use-after-free vulnerability that could allow arbitrar...

Nov 16, 2023
CVE-2023-44336
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious PDF ...

Nov 16, 2023
CVE-2023-48011
7.8

CVE-2023-48011 is a heap-use-after-free vulnerability in GPAC's movie_fragments.c that allows attackers to execute arbitrary code or cause denial of s...

Nov 15, 2023
CVE-2023-21381
7.8

CVE-2023-21381 is a use-after-free vulnerability in Android's Media Resource Manager that allows local arbitrary code execution. This enables local pr...

Oct 30, 2023
CVE-2023-21355
7.8

CVE-2023-21355 is a use-after-free vulnerability in Android's libaudioclient library that allows local privilege escalation without user interaction. ...

Oct 30, 2023
CVE-2023-40140
7.8

This CVE describes a use-after-free vulnerability in Android's InputDevice component that allows local privilege escalation without user interaction. ...

Oct 27, 2023

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,336 CVEs classified as CWE-416, with 195 rated critical and 1,985 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free