CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,357
Total CVEs
198
Critical
2,003
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
105
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 769
2 Google 399
3 Microsoft 261
4 Debian 239
5 Fedoraproject 206
6 Adobe 140
7 Qualcomm 88
8 Foxit 84
9 Apple 77
10 Mozilla 53

All Use After Free CVEs (2,357)

CVE-2021-1029
7.8

CVE-2021-1029 is a local privilege escalation vulnerability in Android's SurfaceFlinger component, allowing an attacker to execute arbitrary code with...

Dec 15, 2021
CVE-2021-1048
7.8

CVE-2021-1048 is a use-after-free vulnerability in the Android kernel's eventpoll subsystem that allows local privilege escalation. An attacker can ex...

Dec 15, 2021
CVE-2021-0929
7.8

CVE-2021-0929 is a use-after-free vulnerability in Android's ION memory management subsystem that allows local attackers to corrupt kernel memory. Thi...

Dec 15, 2021
CVE-2021-44447
7.8

This vulnerability allows remote code execution via specially crafted JT files in Siemens JT Utilities and JTTK libraries. Attackers can exploit a use...

Dec 14, 2021
CVE-2021-4069
7.8

CVE-2021-4069 is a use-after-free vulnerability in Vim that could allow an attacker to execute arbitrary code by tricking a user into opening a specia...

Dec 6, 2021
CVE-2021-44047
7.8

A use-after-free vulnerability in Open Design Alliance Drawings SDK allows remote code execution when processing malicious DWF/DWFX files. Attackers c...

Dec 5, 2021
CVE-2021-43582
7.8

CVE-2021-43582 is a use-after-free vulnerability in Open Design Alliance Drawings SDK that allows remote code execution when processing malicious DWG ...

Nov 22, 2021
CVE-2021-3974
7.8

CVE-2021-3974 is a use-after-free vulnerability in Vim text editor that could allow an attacker to execute arbitrary code by tricking a user into open...

Nov 19, 2021
CVE-2021-37322
7.8

CVE-2021-37322 is a use-after-free vulnerability in GCC's c++filt utility (version 2.26) that can lead to arbitrary code execution or denial of servic...

Nov 18, 2021
CVE-2021-42269
7.8

Adobe Animate versions 21.0.9 and earlier contain a use-after-free vulnerability when processing malformed FLA files. This could allow attackers to ex...

Nov 18, 2021
CVE-2021-42721
7.8

CVE-2021-42721 is a use-after-free vulnerability in Adobe Bridge versions 11.1.1 and earlier that allows arbitrary code execution when processing mali...

Nov 16, 2021
CVE-2021-42706
7.8

CVE-2021-42706 is a use-after-free vulnerability in Advantech WebAccess/MHI Designer that could allow remote attackers to execute arbitrary code or di...

Nov 15, 2021
CVE-2021-43274
7.8

CVE-2021-43274 is a use-after-free vulnerability in the Open Design Alliance Drawings SDK that allows attackers to execute arbitrary code by exploitin...

Nov 14, 2021
CVE-2021-41220
7.8

This CVE describes a memory leak and use-after-free vulnerability in TensorFlow's CollectiveReduceV2 async implementation. Attackers could potentially...

Nov 5, 2021
CVE-2021-43057
7.8

A use-after-free vulnerability in the SELinux PTRACE_TRACEME handler in Linux kernel versions before 5.14.8 allows local attackers to cause memory cor...

Oct 28, 2021
CVE-2021-0936
7.8

This CVE describes a use-after-free vulnerability in the Android kernel's USB accessory driver that could allow local privilege escalation. An attacke...

Oct 25, 2021
CVE-2021-21796
7.8

A use-after-free vulnerability in Nitro Pro PDF's JavaScript engine allows remote code execution when a user opens a malicious PDF document. This affe...

Oct 18, 2021
CVE-2021-40449
7.8

CVE-2021-40449 is a use-after-free vulnerability in the Win32k graphics driver component of Windows. It allows a local authenticated attacker to execu...

Oct 13, 2021
CVE-2021-40725
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when processing a malicious Acr...

Oct 7, 2021
CVE-2021-39842
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malicious P...

Sep 29, 2021
CVE-2021-39836
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC's AcroForm buttonGetIcon action processing. When exploited, it allows arb...

Sep 29, 2021
CVE-2021-39838
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC's AcroForm buttonGetCaption action. If exploited, it allows arbitrary cod...

Sep 29, 2021
CVE-2021-39840
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC's AcroForms processing that could allow arbitrary code execution when a u...

Sep 29, 2021
CVE-2021-41535
7.8

This CVE describes a use-after-free vulnerability in Siemens NX and Solid Edge software when parsing OBJ files. An attacker could exploit this to exec...

Sep 28, 2021
CVE-2021-41537
7.8

A use-after-free vulnerability in Solid Edge SE2021 allows attackers to execute arbitrary code by tricking users into opening malicious OBJ files. Thi...

Sep 28, 2021
CVE-2021-41539
7.8

This vulnerability in Solid Edge SE2021 allows attackers to execute arbitrary code by exploiting a use-after-free bug when parsing malicious OBJ files...

Sep 28, 2021
CVE-2021-0612
7.8

CVE-2021-0612 is a use-after-free vulnerability in MediaTek's m4u (Memory Management Unit) driver that could allow local attackers to escalate privile...

Sep 27, 2021
CVE-2021-37202
7.8

A use-after-free vulnerability in the IFC adapter of Siemens NX 1980 Series and Solid Edge SE2021 allows attackers to execute arbitrary code by tricki...

Sep 14, 2021
CVE-2021-30683
7.8

This is a use-after-free memory corruption vulnerability in macOS that allows malicious applications to execute arbitrary code. It affects macOS Big S...

Sep 8, 2021
CVE-2021-36055
7.8

CVE-2021-36055 is a use-after-free vulnerability in Adobe XMP Toolkit SDK that could allow arbitrary code execution when a user opens a malicious file...

Sep 1, 2021
CVE-2021-30927
7.8

This CVE describes a use-after-free vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileg...

Aug 24, 2021
CVE-2021-30886
7.8

CVE-2021-30886 is a use-after-free vulnerability in Apple operating systems that allows malicious applications to execute arbitrary code with kernel p...

Aug 24, 2021
CVE-2021-28631
7.8

This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF fi...

Aug 24, 2021
CVE-2021-35981
7.8

CVE-2021-35981 is a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF fil...

Aug 20, 2021
CVE-2020-18897
7.8

This use-after-free vulnerability in libpff allows attackers to cause denial of service or execute arbitrary code by processing a malicious PFF (Perso...

Aug 19, 2021
CVE-2021-34486
7.8

This vulnerability allows attackers to gain SYSTEM-level privileges on Windows systems by exploiting a use-after-free bug in Windows Event Tracing. It...

Aug 12, 2021
CVE-2021-37179
7.8

This vulnerability in Solid Edge SE2021 allows attackers to execute arbitrary code by tricking users into opening malicious OBJ files. The use-after-f...

Aug 10, 2021
CVE-2021-34849
7.8

CVE-2021-34849 is a use-after-free vulnerability in Foxit PDF Reader that allows remote attackers to execute arbitrary code. Attackers can exploit thi...

Aug 4, 2021
CVE-2021-34851
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Aug 4, 2021
CVE-2021-34853
7.8

CVE-2021-34853 is a use-after-free vulnerability in Foxit PDF Reader that allows remote code execution when users open malicious PDF files or visit ma...

Aug 4, 2021
CVE-2021-34839
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected Foxit PDF Reader installations by tricking users into opening malicio...

Aug 4, 2021
CVE-2021-34841
7.8

CVE-2021-34841 is a use-after-free vulnerability in Foxit PDF Reader that allows remote attackers to execute arbitrary code when users open malicious ...

Aug 4, 2021
CVE-2021-34843
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Aug 4, 2021
CVE-2021-34845
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Aug 4, 2021
CVE-2021-34847
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Aug 4, 2021
CVE-2021-34831
7.8

CVE-2021-34831 is a use-after-free vulnerability in Foxit Reader that allows remote attackers to execute arbitrary code when users open malicious PDF ...

Aug 4, 2021
CVE-2021-34833
7.8

CVE-2021-34833 is a use-after-free vulnerability in Foxit PDF Reader that allows remote attackers to execute arbitrary code. Attackers can exploit thi...

Aug 4, 2021
CVE-2021-34835
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Aug 4, 2021
CVE-2021-34837
7.8

CVE-2021-34837 is a use-after-free vulnerability in Foxit PDF Reader that allows remote attackers to execute arbitrary code when users open malicious ...

Aug 4, 2021
CVE-2021-34498
7.8

This vulnerability in Windows Graphics Device Interface (GDI) allows an attacker to execute arbitrary code with elevated privileges. It affects Window...

Jul 14, 2021

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,357 CVEs classified as CWE-416, with 198 rated critical and 2,003 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free