CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,342
Total CVEs
195
Critical
1,991
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
105
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 769
2 Google 397
3 Microsoft 261
4 Debian 236
5 Fedoraproject 202
6 Adobe 140
7 Qualcomm 85
8 Foxit 84
9 Apple 77
10 Mozilla 53

All Use After Free CVEs (2,342)

CVE-2023-44336
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious PDF ...

Nov 16, 2023
CVE-2023-48011
7.8

CVE-2023-48011 is a heap-use-after-free vulnerability in GPAC's movie_fragments.c that allows attackers to execute arbitrary code or cause denial of s...

Nov 15, 2023
CVE-2023-21381
7.8

CVE-2023-21381 is a use-after-free vulnerability in Android's Media Resource Manager that allows local arbitrary code execution. This enables local pr...

Oct 30, 2023
CVE-2023-21355
7.8

CVE-2023-21355 is a use-after-free vulnerability in Android's libaudioclient library that allows local privilege escalation without user interaction. ...

Oct 30, 2023
CVE-2023-40140
7.8

This CVE describes a use-after-free vulnerability in Android's InputDevice component that allows local privilege escalation without user interaction. ...

Oct 27, 2023
CVE-2023-40404
7.8

This CVE describes a use-after-free vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. Attackers coul...

Oct 25, 2023
CVE-2023-34366
7.8

This is a use-after-free vulnerability in Ichitaro 2023's Figure stream parser that allows arbitrary code execution when a user opens a malicious docu...

Oct 19, 2023
CVE-2023-45898
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's ext4 filesystem driver, specifically in the extents status handling code. Atta...

Oct 16, 2023
CVE-2023-5345
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SMB client component that allows local attackers to escalate privileges. The f...

Oct 3, 2023
CVE-2023-5197
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's netfilter nf_tables component. It allows local attackers to escalate privilege...

Sep 27, 2023
CVE-2023-41995
7.8

This CVE describes a use-after-free vulnerability in Apple's iOS, iPadOS, and macOS that allows a malicious app to execute arbitrary code with kernel ...

Sep 27, 2023
CVE-2023-41071
7.8

This CVE-2023-41071 is a use-after-free vulnerability in Apple operating systems that allows an app to execute arbitrary code with kernel privileges. ...

Sep 27, 2023
CVE-2023-4921
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's qfq scheduler component that allows local attackers to escalate privileges. Th...

Sep 12, 2023
CVE-2023-38161
7.8

This Windows Graphics Device Interface (GDI) vulnerability allows an attacker to execute arbitrary code with elevated privileges. It affects Windows s...

Sep 12, 2023
CVE-2023-36804
7.8

This Windows GDI vulnerability allows local attackers to escalate privileges on affected systems. An authenticated attacker could exploit this to gain...

Sep 12, 2023
CVE-2023-36802
7.8

This vulnerability in Microsoft Streaming Service Proxy allows attackers to escalate privileges on affected Windows systems. An authenticated attacker...

Sep 12, 2023
CVE-2023-36760
7.8

CVE-2023-36760 is a use-after-free vulnerability in Microsoft 3D Viewer that allows remote code execution when a user opens a specially crafted malici...

Sep 12, 2023
CVE-2023-38075
7.8

This CVE describes a use-after-free vulnerability in Siemens JT2Go, Teamcenter Visualization, and Tecnomatix Plant Simulation software. Attackers can ...

Sep 12, 2023
CVE-2022-28835
7.8

Adobe InCopy versions 17.1 and earlier (and 16.4.1 and earlier) contain a use-after-free vulnerability that could allow attackers to execute arbitrary...

Sep 11, 2023
CVE-2022-34224
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader that could allow an attacker to execute arbitrary code on a victim's system....

Sep 11, 2023
CVE-2022-30644
7.8

This CVE describes a use-after-free vulnerability in Adobe Illustrator that could allow an attacker to execute arbitrary code on a victim's system. Th...

Sep 7, 2023
CVE-2023-4622
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's af_unix component that allows local attackers to escalate privileges. The race...

Sep 6, 2023
CVE-2023-4206
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's net/sched: cls_route component that allows local attackers to escalate privile...

Sep 6, 2023
CVE-2023-4208
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 traffic control subsystem. It allows a local attacker to es...

Sep 6, 2023
CVE-2023-3777
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's netfilter nf_tables component. It allows a local attacker to escalate privileg...

Sep 6, 2023
CVE-2021-21088
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF fi...

Sep 6, 2023
CVE-2023-4750
7.8

CVE-2023-4750 is a use-after-free vulnerability in Vim text editor that could allow an attacker to execute arbitrary code by tricking a user into open...

Sep 4, 2023
CVE-2020-21722
7.8

CVE-2020-21722 is a buffer overflow vulnerability in oggvideotools 0.9.1 that allows remote attackers to execute arbitrary code by tricking users into...

Aug 22, 2023
CVE-2020-19725
7.8

CVE-2020-19725 is a use-after-free vulnerability in Z3 theorem prover that occurs during constraint simplification in pdd_simplifier.cpp. This vulnera...

Aug 22, 2023
CVE-2023-38211
7.8

Adobe Dimension 3.4.9 contains a use-after-free vulnerability that could allow an attacker to execute arbitrary code on a victim's system when they op...

Aug 9, 2023
CVE-2023-36895
7.8

CVE-2023-36895 is a use-after-free vulnerability in Microsoft Outlook that allows remote code execution when processing specially crafted email messag...

Aug 8, 2023
CVE-2023-35382
7.8

This is a Windows kernel use-after-free vulnerability that allows local attackers to gain SYSTEM privileges. It affects Windows systems where an authe...

Aug 8, 2023
CVE-2023-35380
7.8

This Windows kernel vulnerability allows an authenticated attacker to execute arbitrary code with elevated SYSTEM privileges. It affects Windows opera...

Aug 8, 2023
CVE-2023-39549
7.8

A use-after-free vulnerability in Solid Edge SE2023 allows attackers to execute arbitrary code by tricking users into opening malicious DWG files. Thi...

Aug 8, 2023
CVE-2023-28830
7.8

A use-after-free vulnerability in Siemens JT2Go, Solid Edge, and Teamcenter Visualization applications allows remote code execution when parsing malic...

Aug 8, 2023
CVE-2023-22277
7.8

A use-after-free vulnerability in Omron CX-Programmer versions 9.79 and earlier allows attackers to cause information disclosure or execute arbitrary ...

Aug 3, 2023
CVE-2023-22314
7.8

A use-after-free vulnerability in Omron CX-Programmer versions 9.79 and earlier allows attackers to cause information disclosure or arbitrary code exe...

Aug 3, 2023
CVE-2023-35993
7.8

This is a use-after-free vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It affe...

Jul 27, 2023
CVE-2023-32381
7.8

This CVE describes a use-after-free vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileg...

Jul 27, 2023
CVE-2023-3609
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component that allows local privilege escalation. Attackers...

Jul 21, 2023
CVE-2023-2762
7.8

A use-after-free vulnerability in SOLIDWORKS Desktop allows attackers to execute arbitrary code when users open malicious SLDPRT files. This affects S...

Jul 12, 2023
CVE-2023-35313
7.8

This vulnerability allows remote code execution through the Windows Online Certificate Status Protocol (OCSP) SnapIn component. Attackers can exploit ...

Jul 11, 2023
CVE-2023-33149
7.8

This vulnerability allows remote code execution through specially crafted Office documents containing malicious graphics. Attackers can exploit this b...

Jul 11, 2023
CVE-2023-21756
7.8

This vulnerability allows an attacker to gain SYSTEM-level privileges on Windows systems by exploiting a use-after-free bug in the Win32k driver. It a...

Jul 11, 2023
CVE-2023-3269
7.8

This Linux kernel vulnerability allows attackers to exploit incorrect lock handling in virtual memory area management, leading to use-after-free condi...

Jul 11, 2023
CVE-2023-31248
7.8

This CVE-2023-31248 is a use-after-free vulnerability in the Linux kernel's nftables subsystem that allows local attackers to escalate privileges. The...

Jul 5, 2023
CVE-2023-3390
7.8

A use-after-free vulnerability in the Linux kernel's netfilter subsystem allows local attackers with user access to escalate privileges. The flaw occu...

Jun 28, 2023
CVE-2023-21147
7.8

This CVE describes a use-after-free vulnerability in the Android kernel's I2C device driver that allows local privilege escalation without user intera...

Jun 28, 2023
CVE-2023-25001
7.8

A use-after-free vulnerability in Autodesk Navisworks allows malicious SKP files to trigger memory corruption, potentially leading to arbitrary code e...

Jun 27, 2023
CVE-2023-28287
7.8

CVE-2023-28287 is a use-after-free vulnerability in Microsoft Publisher that allows remote code execution when a user opens a specially crafted Publis...

Jun 17, 2023

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,342 CVEs classified as CWE-416, with 195 rated critical and 1,991 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free