CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,389
Total CVEs
211
Critical
2,021
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
117
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 769
2 Google 402
3 Microsoft 261
4 Debian 241
5 Fedoraproject 209
6 Adobe 147
7 Qualcomm 88
8 Foxit 84
9 Apple 77
10 Mozilla 55

All Use After Free CVEs (2,389)

CVE-2024-33055
6.7

This vulnerability allows attackers to cause memory corruption by making specific IOCTL calls to unmap DMA buffers in Qualcomm components. It affects ...

Jan 6, 2025
CVE-2018-9439
6.7

This CVE describes a use-after-free vulnerability in the Linux kernel's af_packet.c module. It allows local attackers to escalate privileges to kernel...

Dec 5, 2024
CVE-2024-33053
6.7

CVE-2024-33053 is a use-after-free vulnerability in Qualcomm's CVP buffer management that allows memory corruption when multiple threads simultaneousl...

Dec 2, 2024
CVE-2024-23370
6.7

This vulnerability allows memory corruption when two processes concurrently create and destroy the same HAB virtual channel via IOCTL calls. It affect...

Oct 7, 2024
CVE-2023-43543
6.7

This CVE describes a use-after-free vulnerability in Qualcomm audio components where a race condition between allocation and deallocation of graph obj...

Jun 3, 2024
CVE-2023-43521
6.7

This CVE describes a use-after-free vulnerability in Qualcomm components where registering multiple listeners with the same file descriptor can cause ...

May 6, 2024
CVE-2023-21042
6.7

This CVE describes a use-after-free vulnerability in the Android kernel that could allow local privilege escalation. Attackers with system execution p...

Mar 24, 2023
CVE-2025-47333
6.6

This vulnerability allows memory corruption in Qualcomm's cryptographic driver when handling buffer mapping operations. Attackers could potentially ex...

Jan 7, 2026
CVE-2024-45544
6.6

This vulnerability allows memory corruption through improper handling of IOCTL calls when adding route entries in Qualcomm hardware. Attackers could p...

Apr 7, 2025
CVE-2024-45540
6.6

This vulnerability allows memory corruption through improper handling of IOCTL map buffer requests from userspace. Attackers could potentially execute...

Apr 7, 2025
CVE-2024-38411
6.6

This CVE describes a memory corruption vulnerability in Qualcomm components where improper validation of user-space buffers during IOCTL calls allows ...

Feb 3, 2025
CVE-2026-24917
6.5

This CVE describes a use-after-free vulnerability in a security module that could allow attackers to crash affected systems, potentially causing denia...

Feb 6, 2026
CVE-2026-21921
6.5

A Use After Free vulnerability in Juniper's chassis daemon allows authenticated low-privilege attackers to cause denial-of-service by repeatedly subsc...

Jan 15, 2026
CVE-2026-0885
6.5

This CVE describes a use-after-free vulnerability in the JavaScript garbage collection component of Mozilla products. Attackers could exploit this to ...

Jan 13, 2026
CVE-2025-43511
6.5

This CVE describes a use-after-free vulnerability in Apple's WebKit browser engine that affects multiple Apple operating systems and Safari. Processin...

Dec 12, 2025
CVE-2025-65407
6.5

This vulnerability is a use-after-free flaw in Live555 Streaming Media's MPEG1or2Demux component that allows attackers to cause denial of service by s...

Dec 1, 2025
CVE-2025-65405
6.5

This vulnerability allows attackers to cause a Denial of Service (DoS) by exploiting a use-after-free bug in Live555's ADTS/AAC file parsing. Attacker...

Dec 1, 2025
CVE-2025-29699
6.5

NetSurf 3.11 contains a use-after-free vulnerability in the dom_node_set_text_content function that could allow memory corruption. This affects users ...

Nov 3, 2025
CVE-2025-57109
6.5

CVE-2025-57109 is a heap use-after-free vulnerability in Kitware VTK's GLTF file importer that could allow attackers to crash applications or potentia...

Oct 30, 2025
CVE-2025-62504
6.5

Envoy proxy versions before 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain a use-after-free vulnerability in the Lua filter. When a Lua script rewrites ...

Oct 16, 2025
CVE-2025-43216
6.5

A use-after-free vulnerability in Apple's Safari browser and related WebKit components allows attackers to cause unexpected crashes by processing mali...

Jul 30, 2025
CVE-2025-3631
6.5

A use-after-free vulnerability (CWE-416) in IBM MQ 9.3 and 9.4 allows a malicious client to crash the AMQRMPPA channel process via SIGSEGV when connec...

Jul 11, 2025
CVE-2025-23106
6.5

A use-after-free vulnerability in Samsung Exynos 2200, 1480, and 2400 mobile processors allows local attackers to escalate privileges. This affects de...

Jun 4, 2025
CVE-2025-1704
6.5

This vulnerability in ChromeOS ComponentInstaller allows enrolled users with physical access to unenroll devices from enterprise management and interc...

Apr 16, 2025
CVE-2025-3028
6.5

This vulnerability allows JavaScript code to trigger a use-after-free condition during XSLT document transformations in Mozilla browsers and email cli...

Apr 1, 2025
CVE-2024-4949
6.5

This vulnerability is a use-after-free memory corruption flaw in Chrome's V8 JavaScript engine. It allows remote attackers to potentially execute arbi...

May 15, 2024
CVE-2024-27217
6.5

CVE-2024-27217 is a use-after-free vulnerability in OpenHarmony v4.0.0 and earlier that allows local attackers to execute arbitrary code within pre-in...

May 7, 2024
CVE-2023-32135
6.5

A use-after-free vulnerability in Sante DICOM Viewer Pro allows remote attackers to disclose sensitive information when users open malicious DCM files...

May 3, 2024
CVE-2025-58307
6.4

A use-after-free vulnerability in the screen recording framework module could allow attackers to crash affected systems, affecting availability. This ...

Nov 28, 2025
CVE-2024-40885
6.4

A use-after-free vulnerability in UEFI firmware on specific Intel server BIOS allows privileged local users to potentially escalate privileges. This a...

Nov 13, 2024
CVE-2023-21055
6.4

This CVE describes a use-after-free vulnerability in the Android kernel's DIT (Data Interface Technology) driver due to a race condition in the dit_ha...

Mar 24, 2023
CVE-2026-25507
6.3

A use-after-free vulnerability in the ESP-IDF BLE provisioning transport layer allows remote attackers to trigger invalid memory access via Bluetooth ...

Feb 4, 2026
CVE-2021-47375
6.2

This is a use-after-free vulnerability in the Linux kernel's blktrace subsystem that allows local attackers to cause a kernel NULL pointer dereference...

May 21, 2024
CVE-2025-14372
6.1

A use-after-free vulnerability in Google Chrome's Password Manager allows remote attackers to potentially escape the browser sandbox via a crafted HTM...

Dec 12, 2025
CVE-2025-20062
6.1

A use-after-free vulnerability in Intel PROSet/Wireless WiFi Software for Windows allows an unauthenticated attacker on the same network to potentiall...

May 13, 2025
CVE-2024-57959
6.1

A Use-After-Free vulnerability in the display module allows attackers to exploit memory corruption after memory has been freed. This could lead to abn...

Feb 6, 2025
CVE-2025-62408
5.9

A denial-of-service vulnerability in c-ares resolver library versions 1.32.3 through 1.34.5 causes queries to terminate after maximum attempts when us...

Dec 8, 2025
CVE-2024-49023
5.9

This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by exploiting a use-after-...

Oct 18, 2024
CVE-2024-32974
5.9

This CVE describes a use-after-free vulnerability in Envoy's QUIC implementation that can cause a crash when processing HTTP/3 requests. The vulnerabi...

Jun 4, 2024
CVE-2025-58311
5.8

This CVE describes a use-after-free vulnerability in the USB driver module that could allow an attacker to execute arbitrary code or cause a system cr...

Nov 28, 2025
CVE-2025-46710
5.7

This CVE describes a use-after-free vulnerability in Imagination Technologies GPU drivers that could allow attackers to cause kernel exceptions or pot...

Jun 16, 2025
CVE-2025-31197
5.7

This vulnerability allows an attacker on the same local network to cause unexpected application termination (denial of service) on affected Apple devi...

Apr 29, 2025
CVE-2024-8947
5.6

This critical vulnerability in MicroPython's objarray component allows attackers to trigger a use-after-free condition when bytes objects are resized ...

Sep 17, 2024
CVE-2026-24927
5.5

This CVE describes an out-of-bounds access vulnerability in a frequency modulation module that could allow attackers to cause denial of service condit...

Feb 6, 2026
CVE-2025-65503
5.5

A use-after-free vulnerability in Redboltz async_mqtt 10.2.5 allows local users to cause denial of service by triggering SSL initialization failures, ...

Nov 24, 2025
CVE-2025-61842
5.5

Format Plugins versions 1.1.1 and earlier contain a Use After Free vulnerability that could allow memory exposure when processing malicious files. An ...

Nov 11, 2025
CVE-2022-50363
5.5

A use-after-free vulnerability in the Linux kernel's skmsg subsystem where alloc_sk_msg() could be called from a non-sleepable context without proper ...

Sep 17, 2025
CVE-2022-50288
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's qlcnic driver. When qlcnic_dcb_enable() fails under out-of-memory conditions, ...

Sep 15, 2025
CVE-2025-39785
5.5

A use-after-free vulnerability in the Linux kernel's hibmc DRM driver allows local attackers to cause kernel crashes or potentially execute arbitrary ...

Sep 11, 2025
CVE-2025-39721
5.5

A use-after-free vulnerability in the Linux kernel's Intel QAT crypto driver allows kernel crashes when repeatedly loading/unloading device-specific d...

Sep 5, 2025

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,389 CVEs classified as CWE-416, with 211 rated critical and 2,021 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free