CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,357
Total CVEs
198
Critical
2,003
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
105
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 769
2 Google 399
3 Microsoft 261
4 Debian 239
5 Fedoraproject 206
6 Adobe 140
7 Qualcomm 88
8 Foxit 84
9 Apple 77
10 Mozilla 53

All Use After Free CVEs (2,357)

CVE-2025-12105
7.5

A use-after-free vulnerability in libsoup's HTTP/2 message queue handling allows remote attackers to crash applications by sending specific HTTP/2 req...

Oct 23, 2025
CVE-2025-48008
7.5

This vulnerability affects F5 BIG-IP systems with TCP profiles configured with Multipath TCP (MPTCP) enabled on virtual servers. Under specific traffi...

Oct 15, 2025
CVE-2025-55326
7.5

A use-after-free vulnerability in Windows Connected Devices Platform Service allows unauthorized attackers to execute arbitrary code remotely over a n...

Oct 14, 2025
CVE-2025-62170
7.5

A use-after-free vulnerability in rAthena's RODEX functionality allows unauthenticated attackers to crash the map-server, causing denial of service. T...

Oct 13, 2025
CVE-2025-11234
7.5

This CVE describes a use-after-free vulnerability in QEMU's WebSocket handling for VNC. A malicious client can cause denial of service by exploiting a...

Oct 3, 2025
CVE-2025-54588
7.5

This CVE describes a use-after-free vulnerability in Envoy's DNS cache within the Dynamic Forward Proxy implementation. It can cause abnormal process ...

Sep 3, 2025
CVE-2025-57616
7.5

A use-after-free vulnerability in rust-ffmpeg's write_interleaved method allows memory corruption through Rust aliasing rule violations. This affects ...

Sep 2, 2025
CVE-2025-46709
7.5

This CVE describes a use-after-free vulnerability in Imagination Technologies GPU drivers that could allow attackers to cause kernel memory leaks or t...

Aug 9, 2025
CVE-2025-27038
KEV 7.5

This vulnerability allows memory corruption in Chrome's graphics rendering through Adreno GPU drivers, potentially enabling arbitrary code execution. ...

Jun 3, 2025
CVE-2025-1706
7.5

This vulnerability allows non-privileged users to trigger use-after-free kernel exceptions through improper GPU system calls, potentially leading to p...

May 17, 2025
CVE-2025-29831
7.5

CVE-2025-29831 is a use-after-free vulnerability in Microsoft's Remote Desktop Gateway Service that allows unauthorized attackers to execute arbitrary...

May 13, 2025
CVE-2025-30194
7.5

This vulnerability allows attackers to cause a denial of service in DNSdist by sending specially crafted DNS-over-HTTPS (DoH) requests that trigger a ...

Apr 29, 2025
CVE-2025-26687
7.5

CVE-2025-26687 is a use-after-free vulnerability in Windows Win32K graphics subsystem that allows local attackers to escalate privileges. This affects...

Apr 8, 2025
CVE-2025-1012
7.5

A race condition during concurrent delazification in Mozilla products could lead to use-after-free vulnerabilities, potentially allowing attackers to ...

Feb 4, 2025
CVE-2025-21296
7.5

This CVE describes a use-after-free vulnerability (CWE-416) in Microsoft's BranchCache service that allows remote attackers to execute arbitrary code ...

Jan 14, 2025
CVE-2024-4741
7.5

This CVE describes a use-after-free vulnerability in OpenSSL's SSL_free_buffers function. Only applications that directly call this rarely-used functi...

Nov 13, 2024
CVE-2024-33068
7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted MBSSID Information Element fragments i...

Nov 4, 2024
CVE-2024-38138
7.5

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Windows Deployment Services (WDS). Attackers can explo...

Aug 13, 2024
CVE-2024-33010
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted MBSSID Information Element fragments in ...

Aug 5, 2024
CVE-2024-36844
7.5

CVE-2024-36844 is a use-after-free vulnerability in libmodbus v3.1.6 that allows attackers to cause Denial of Service (DoS) by sending a crafted messa...

May 31, 2024
CVE-2021-47259
7.5

This Linux kernel vulnerability in the NFS client allows a use-after-free condition when mounting multiple exports from the same server through differ...

May 21, 2024
CVE-2024-30416
7.5

This CVE-2024-30416 is a Use After Free vulnerability in a driver module that could allow attackers to crash affected systems, causing denial of servi...

Apr 7, 2024
CVE-2024-30807
7.5

This vulnerability is a heap-use-after-free flaw in Bento4 v1.6.0-641-2-g1529b83 that occurs during destruction of AP4_UnknownAtom objects. It allows ...

Apr 2, 2024
CVE-2024-30809
7.5

A heap-use-after-free vulnerability in Bento4 v1.6.0-641-2-g1529b83 allows attackers to cause denial of service by triggering memory corruption in the...

Apr 2, 2024
CVE-2024-27284
7.5

This is a use-after-free vulnerability in the cassandra-rs Rust driver for Cassandra databases. When code accesses an iterator item after the iterator...

Feb 29, 2024
CVE-2024-26455
7.5

CVE-2024-26455 is a use-after-free vulnerability in fluent-bit's custom_calyptia plugin that could allow attackers to execute arbitrary code or cause ...

Feb 26, 2024
CVE-2024-23322
7.5

Envoy proxy crashes when specific timeout configurations overlap, causing a denial of service. This affects Envoy deployments with hedge_on_per_try_ti...

Feb 9, 2024
CVE-2024-24262
7.5

CVE-2024-24262 is a Use-After-Free vulnerability in media-server v1.0.0's SIP transaction timer handling. This allows attackers to potentially execute...

Feb 5, 2024
CVE-2024-25062
7.5

A use-after-free vulnerability in libxml2's XML Reader interface when processing crafted XML documents with DTD validation and XInclude expansion enab...

Feb 4, 2024
CVE-2024-21307
7.5

This vulnerability allows an attacker to execute arbitrary code on a victim's system by tricking them into connecting to a malicious RDP server. It af...

Jan 9, 2024
CVE-2023-52266
7.5

CVE-2023-52266 is a use-after-free vulnerability in ehttp 1.0.6's epoll_socket.cpp read_func. An attacker can trigger this by making many connections ...

Dec 31, 2023
CVE-2023-46751
7.5

A use-after-free vulnerability in Ghostscript's gdev_prn_open_printer_seekable() function allows remote attackers to crash the application via a dangl...

Dec 6, 2023
CVE-2023-46768
7.5

A use-after-free vulnerability (CWE-416) in the idmap module of Huawei HarmonyOS and EMUI systems allows attackers to cause abnormal feature behavior ...

Nov 8, 2023
CVE-2023-5728
7.5

A use-after-free vulnerability in Firefox, Firefox ESR, and Thunderbird garbage collection could allow attackers to cause a crash or potentially execu...

Oct 25, 2023
CVE-2023-44095
7.5

This CVE describes a Use-After-Free vulnerability in the surfaceflinger module of Huawei/HarmonyOS devices. Successful exploitation can cause system c...

Oct 11, 2023
CVE-2023-40632
7.5

CVE-2023-40632 is a use-after-free vulnerability in the jpg driver that could allow remote attackers to disclose sensitive information without requiri...

Oct 8, 2023
CVE-2023-2680
7.5

CVE-2023-2680 is a use-after-free vulnerability in qemu-kvm virtualization software that occurs due to an incomplete fix for CVE-2021-3750. This allow...

Sep 13, 2023
CVE-2022-48560
7.5

CVE-2022-48560 is a use-after-free vulnerability in Python's heapq.heappushpop function that can lead to memory corruption. This affects Python applic...

Aug 22, 2023
CVE-2021-32421
7.5

CVE-2021-32421 is a heap use-after-free vulnerability in dpic's deletestringbox() function that allows attackers to execute arbitrary code or cause de...

Aug 22, 2023
CVE-2023-38184
7.5

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running LDAP services by exploiting a use-after-free memory co...

Aug 8, 2023
CVE-2023-34494
7.5

NanoMQ 0.16.5 contains a heap-use-after-free vulnerability in the nano_ctx_send function that allows attackers to potentially execute arbitrary code o...

Jun 12, 2023
CVE-2023-33657
7.5

A use-after-free vulnerability in NanoMQ 0.17.2 allows attackers to trigger memory corruption by calling nni_mqtt_msg_get_publish_property(). This can...

Jun 8, 2023
CVE-2023-28319
7.5

CVE-2023-28319 is a use-after-free vulnerability in curl/libcurl versions before 8.1.0 that occurs during SSH server public key verification. When ver...

May 26, 2023
CVE-2023-24833
7.5

CVE-2023-24833 is a use-after-free vulnerability in Hermes JavaScript engine's BigIntPrimitive addition that allows attackers to leak raw heap data fr...

May 18, 2023
CVE-2023-2135
7.5

This is a use-after-free vulnerability in Chrome's DevTools that could allow heap corruption. Attackers could potentially execute arbitrary code or cr...

Apr 19, 2023
CVE-2022-43716
7.5

A denial-of-service vulnerability in the webserver of multiple Siemens SIMATIC communication processors allows attackers to crash the webserver, causi...

Apr 11, 2023
CVE-2022-30539
7.5

This CVE describes a use-after-free vulnerability in BIOS firmware for certain Intel processors. A privileged user could exploit this via local access...

Feb 16, 2023
CVE-2022-40016
7.5

A Use After Free vulnerability in ireader media-server's librtmp component allows attackers to cause denial of service by exploiting memory corruption...

Feb 15, 2023
CVE-2022-1485
7.5

This vulnerability is a use-after-free flaw in Chrome's File System API that allows remote attackers to potentially exploit heap corruption via a craf...

Jul 26, 2022
CVE-2022-1487
7.5

This is a use-after-free vulnerability in Google Chrome's Ozone display system that could allow remote attackers to exploit heap corruption. Attackers...

Jul 26, 2022

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,357 CVEs classified as CWE-416, with 198 rated critical and 2,003 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free