CWE-416: Use After Free
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
Yearly Trend
Top Affected Vendors
All Use After Free CVEs (2,357)
This vulnerability is a use-after-free memory corruption flaw in iOS/iPadOS WebKit that allows arbitrary code execution when processing malicious web ...
Dec 8, 2020CVE-2020-9996 is a use-after-free vulnerability in Apple operating systems that allows malicious applications to elevate privileges. This affects macO...
Dec 8, 2020This CVE-2020-9981 is a use-after-free vulnerability in Apple's memory management that allows arbitrary code execution when processing malicious files...
Dec 8, 2020This CVE describes a use-after-free vulnerability in the Linux kernel's futex implementation. A local attacker can exploit this flaw to corrupt system...
Dec 3, 2020CVE-2020-14351 is a use-after-free vulnerability in the Linux kernel's perf subsystem that allows local attackers with permission to monitor performan...
Dec 3, 2020This vulnerability is a use-after-free flaw in Intel's Trusted Execution Engine (TXE) kernel mode driver that allows an authenticated local attacker t...
Nov 12, 2020This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when processing malicious JavaScript...
Nov 5, 2020This CVE describes a use-after-free vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when processing malicious PDF f...
Nov 5, 2020CVE-2020-3851 is a use-after-free vulnerability in macOS that allows an application to gain elevated privileges. This affects macOS High Sierra, Mojav...
Oct 27, 2020This is a use-after-free vulnerability in specific Huawei smartphone models that allows attackers to execute arbitrary code. Attackers need to trick u...
Oct 19, 2020CVE-2020-16929 is a remote code execution vulnerability in Microsoft Excel caused by improper memory object handling. An attacker can execute arbitrar...
Oct 16, 2020This CVE describes a use-after-free vulnerability in the Android kernel's binder driver due to improper locking. It allows local attackers to escalate...
Oct 14, 2020This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious GIF files in Foxit PhantomPDF. It affect...
Oct 13, 2020NVIDIA Virtual GPU Manager contains a use-after-free vulnerability in the vGPU plugin that could allow attackers to cause denial of service, execute a...
Oct 2, 2020This CVE describes a use-after-free vulnerability in Android's SurfaceFlinger graphics server due to improper locking. It allows local attackers to es...
Sep 17, 2020A use-after-free vulnerability in Nitro Pro PDF software allows attackers to execute arbitrary code by tricking victims into opening malicious PDF doc...
Sep 17, 2020This CVE describes a use-after-free vulnerability in the Linux kernel's cgroups feature due to a flawed backport of a security patch. It allows local ...
Sep 10, 2020This CVE describes a use-after-free vulnerability in Qualcomm Snapdragon chipsets' diag client map table. An attacker could potentially execute arbitr...
Sep 9, 2020CVE-2020-24346 is a use-after-free vulnerability in njs (NGINX JavaScript) through version 0.4.3 that allows attackers to potentially execute arbitrar...
Aug 13, 2020A use-after-free vulnerability in GhostScript's XPS image processing allows remote attackers to execute arbitrary code via a malicious PDF file. This ...
Aug 13, 2020This vulnerability allows local privilege escalation in Android's media server through a use-after-free bug in NuPlayerDriver.cpp. Attackers can explo...
Aug 11, 2020CVE-2019-14037 is a use-after-free vulnerability in Qualcomm Snapdragon socket handling that allows attackers to potentially execute arbitrary code or...
Jul 30, 2020This vulnerability allows local attackers to escalate privileges on Windows systems by exploiting a use-after-free bug in the Windows Graphics Compone...
Jul 14, 2020CVE-2020-9567 is a use-after-free vulnerability in Adobe Bridge that allows attackers to execute arbitrary code on affected systems. This affects user...
Jun 26, 2020CVE-2020-9606 is a use-after-free vulnerability in Adobe Acrobat and Reader that could allow attackers to execute arbitrary code on affected systems. ...
Jun 25, 2020CVE-2020-3642 is a use-after-free vulnerability in Qualcomm Snapdragon camera drivers that allows local attackers to execute arbitrary code or cause d...
Jun 22, 2020This is a Windows kernel-mode driver vulnerability that allows local attackers to escalate privileges from a lower-privileged account to SYSTEM level....
Jun 9, 2020This vulnerability allows attackers to trigger a NULL pointer dereference in Qualcomm Snapdragon chipsets when posting events on RT FIFO. Successful e...
Jun 2, 2020This is a use-after-free vulnerability in Qualcomm's graphics buffer management for HDR blit operations when unsupported color modes are encountered. ...
Jun 2, 2020This vulnerability allows an unprivileged local user to trigger a use-after-free condition in FreeBSD's SCTP implementation when an application attemp...
May 13, 2020This CVE describes a use-after-free vulnerability in the Linux kernel's BFQ I/O scheduler. Attackers with local access can exploit this to cause denia...
May 5, 2020This vulnerability in Foxit Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files or visiting ma...
Apr 22, 2020This vulnerability in Foxit Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing spe...
Apr 22, 2020A heap use-after-free vulnerability in systemd before version v245-rc1 allows local unprivileged attackers to crash systemd services or potentially ex...
Mar 31, 2020This vulnerability in Hancom Office's hncbd90 component allows attackers to trigger a use-after-free memory corruption by opening a specially crafted ...
Mar 19, 2020A use-after-free vulnerability in Qualcomm Snapdragon chipsets allows attackers to potentially execute arbitrary code or cause denial of service when ...
Mar 5, 2020CVE-2019-14040 is a use-after-free vulnerability in Qualcomm's qsee (Qualcomm Secure Execution Environment) that allows attackers to execute arbitrary...
Feb 7, 2020A use-after-free vulnerability in the Linux kernel's mISDN subsystem allows potential memory corruption when the HFC_cleanup() function is called duri...
May 21, 2024CVE-2022-23090 is a use-after-free vulnerability in FreeBSD's asynchronous I/O implementation where the aio_aqueue function fails to release a credent...
Feb 15, 2024A use-after-free vulnerability in Microsoft Edge (Chromium-based) allows an authenticated attacker to execute arbitrary code remotely over a network. ...
Apr 4, 2025This vulnerability in TensorFlow allows a malicious user to trigger use-after-free behavior when decoding PNG images, potentially leading to memory co...
Feb 4, 2022This is a use-after-free vulnerability in FreeRDP's X11 client implementation where a freed pointer is dereferenced during cleanup. An attacker could ...
Feb 25, 2026A use-after-free vulnerability in Monkey web server's string handling function allows attackers to crash the server by sending specially crafted HTTP ...
Jan 29, 2026A use-after-free vulnerability in Monkey web server's HTTP request handling allows attackers to crash the server by sending a specially crafted HTTP r...
Jan 29, 2026This CVE describes a use-after-free vulnerability in Windows LSASS that allows authenticated attackers to execute arbitrary code remotely over a netwo...
Jan 13, 2026CVE-2025-59946 is a heap use-after-free vulnerability in NanoMQ MQTT broker caused by a data race condition in subscription information handling. This...
Dec 27, 2025This CVE describes a use-after-free vulnerability in Google Chrome on iOS that could allow heap corruption. An attacker could exploit this by tricking...
Nov 14, 2025This CVE describes a use-after-free vulnerability in OpenEXR's Python wrapper that occurs when reading EXR image files. Attackers could exploit this t...
Nov 10, 2025This CVE describes a use-after-free vulnerability in Google Chrome's PageInfo component that could allow heap corruption. Attackers can exploit it by ...
Nov 10, 2025This is a use-after-free vulnerability in Wazuh's w_copy_event_for_log() function that allows compromised agents to send specially crafted messages to...
Oct 29, 2025About Use After Free (CWE-416)
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
Our database tracks 2,357 CVEs classified as CWE-416, with 198 rated critical and 2,003 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.
External reference: View CWE-416 on MITRE CWE →
Monitor Use After Free Vulnerabilities
Get alerted when new Use After Free CVEs affect your infrastructure.
Start Monitoring Free