CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,397
Total CVEs
211
Critical
2,029
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
117
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 770
2 Google 402
3 Microsoft 262
4 Debian 241
5 Fedoraproject 209
6 Adobe 147
7 Qualcomm 90
8 Foxit 84
9 Apple 77
10 Mozilla 56

All Use After Free CVEs (2,397)

CVE-2024-8947
5.6

This critical vulnerability in MicroPython's objarray component allows attackers to trigger a use-after-free condition when bytes objects are resized ...

Sep 17, 2024
CVE-2026-24927
5.5

This CVE describes an out-of-bounds access vulnerability in a frequency modulation module that could allow attackers to cause denial of service condit...

Feb 6, 2026
CVE-2025-65503
5.5

A use-after-free vulnerability in Redboltz async_mqtt 10.2.5 allows local users to cause denial of service by triggering SSL initialization failures, ...

Nov 24, 2025
CVE-2025-61842
5.5

Format Plugins versions 1.1.1 and earlier contain a Use After Free vulnerability that could allow memory exposure when processing malicious files. An ...

Nov 11, 2025
CVE-2022-50363
5.5

A use-after-free vulnerability in the Linux kernel's skmsg subsystem where alloc_sk_msg() could be called from a non-sleepable context without proper ...

Sep 17, 2025
CVE-2022-50288
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's qlcnic driver. When qlcnic_dcb_enable() fails under out-of-memory conditions, ...

Sep 15, 2025
CVE-2025-39785
5.5

A use-after-free vulnerability in the Linux kernel's hibmc DRM driver allows local attackers to cause kernel crashes or potentially execute arbitrary ...

Sep 11, 2025
CVE-2025-39721
5.5

A use-after-free vulnerability in the Linux kernel's Intel QAT crypto driver allows kernel crashes when repeatedly loading/unloading device-specific d...

Sep 5, 2025
CVE-2025-39698
5.5

A use-after-free vulnerability in the Linux kernel's io_uring futex subsystem allows local attackers to potentially cause kernel memory corruption or ...

Sep 5, 2025
CVE-2025-22407
5.5

This CVE describes a use-after-free vulnerability in Android's Bluetooth stack that allows arbitrary code execution without user interaction. It affec...

Aug 26, 2025
CVE-2025-38577
5.5

A use-after-free vulnerability in the Linux kernel's F2FS filesystem can cause kernel panic when evicting inodes. This affects systems using F2FS file...

Aug 19, 2025
CVE-2025-38578
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's F2FS filesystem driver, specifically in the f2fs_sync_inode_meta() function. A...

Aug 19, 2025
CVE-2025-49568
5.5

Adobe Illustrator versions 28.7.8, 29.6.1 and earlier contain a use-after-free vulnerability that could allow attackers to read sensitive memory conte...

Aug 12, 2025
CVE-2025-38449
5.5

A use-after-free vulnerability in the Linux kernel's DRM/GEM subsystem allows a local attacker to cause a kernel crash (segmentation fault) by manipul...

Jul 25, 2025
CVE-2022-50092
5.5

A use-after-free vulnerability in the Linux kernel's device-mapper thin provisioning subsystem allows local attackers to crash the system or potential...

Jun 18, 2025
CVE-2025-37765
5.5

A use-after-free vulnerability in the Linux kernel's Nouveau DRM driver allows local attackers to cause a kernel panic (denial of service) by triggeri...

May 1, 2025
CVE-2025-22024
5.5

A use-after-free vulnerability in the Linux kernel's NFS server (nfsd) allows a root user to trigger a kernel panic or system crash by manipulating li...

Apr 16, 2025
CVE-2023-53016
5.5

This CVE describes a deadlock vulnerability in the Linux kernel's Bluetooth RFCOMM protocol implementation. An attacker could potentially cause a deni...

Mar 27, 2025
CVE-2025-21861
5.5

A use-after-free vulnerability in the Linux kernel's memory migration subsystem where folios (memory pages) with cleared memory cgroup data are incorr...

Mar 12, 2025
CVE-2024-0147
5.5

This CVE describes a use-after-free vulnerability in NVIDIA GPU display drivers for Windows and Linux. An attacker could exploit this to cause denial ...

Jan 28, 2025
CVE-2024-57875
5.5

This CVE addresses a use-after-free vulnerability in the Linux kernel's block layer where the conventional zones bitmap pointer (disk->conv_zones_bitm...

Jan 11, 2025
CVE-2024-8821
5.5

PDF-XChange Editor contains a use-after-free vulnerability in U3D file parsing that allows information disclosure. Attackers can exploit this by trick...

Nov 22, 2024
CVE-2023-4679
5.5

A use-after-free vulnerability in GPAC's gf_filterpacket_del function can cause double-free conditions leading to application crashes. This affects sy...

Nov 15, 2024
CVE-2023-4134
5.5

A use-after-free vulnerability in the cyttsp4_core driver of the Linux kernel allows a local user to crash the system by exploiting improper timer han...

Nov 14, 2024
CVE-2024-50149
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's Xe graphics driver. Attackers could potentially exploit this to cause kernel c...

Nov 7, 2024
CVE-2024-50085
5.5

This is a use-after-free vulnerability in the Linux kernel's MPTCP (Multipath TCP) implementation. It allows attackers with local access to potentiall...

Oct 29, 2024
CVE-2024-49988
5.5

This is a use-after-free vulnerability in the Linux kernel's ksmbd SMB server module. Attackers could potentially exploit this to cause kernel crashes...

Oct 21, 2024
CVE-2024-49867
5.5

A use-after-free vulnerability in the Linux kernel's Btrfs filesystem during unmount can cause kernel crashes or potential privilege escalation. This ...

Oct 21, 2024
CVE-2024-47732
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's IAA crypto driver. The vulnerability exists in dead code that would only trigg...

Oct 21, 2024
CVE-2024-47666
5.5

A use-after-free vulnerability in the Linux kernel's pm80xx SCSI driver allows kernel crashes when late PHY control responses trigger completion on a ...

Oct 9, 2024
CVE-2024-46716
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's Altera MSGDMA driver where DMA descriptors are not properly freed during clean...

Sep 18, 2024
CVE-2024-45013
5.5

A use-after-free vulnerability in the Linux kernel's NVMe driver allows kernel memory corruption when NVMe controller initialization fails. This affec...

Sep 11, 2024
CVE-2024-45107
5.5

CVE-2024-45107 is a use-after-free vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents and bypass ASL...

Sep 5, 2024
CVE-2022-48911
5.5

This is a use-after-free vulnerability in the Linux kernel's netfilter nf_queue component. It allows attackers to potentially crash the kernel or exec...

Aug 22, 2024
CVE-2024-42108
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's rswitch network driver. An attacker could potentially crash the system or exec...

Jul 30, 2024
CVE-2024-41010
5.5

A use-after-free vulnerability in the Linux kernel's BPF subsystem allows local attackers to potentially crash the system or execute arbitrary code. T...

Jul 17, 2024
CVE-2022-48844
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's Bluetooth subsystem where the sent_cmd memory buffer is not properly freed bef...

Jul 16, 2024
CVE-2024-38385
5.5

A use-after-free vulnerability in the Linux kernel's interrupt descriptor handling allows an attacker to potentially crash the system or execute arbit...

Jun 25, 2024
CVE-2023-52803
5.5

This is a use-after-free vulnerability in the Linux kernel's SUNRPC client that occurs when cleaning up pipefs dentries. It allows attackers to potent...

May 21, 2024
CVE-2021-47299
5.5

This is a use-after-free vulnerability in the Linux kernel's XDP (eXpress Data Path) subsystem that occurs during BPF link cleanup. It allows local at...

May 21, 2024
CVE-2024-35865
5.5

A use-after-free vulnerability in the Linux kernel's SMB client could allow an attacker to crash the system or potentially execute arbitrary code. Thi...

May 19, 2024
CVE-2024-35801
5.5

A Linux kernel vulnerability where cached XFD state becomes out of sync with the actual MSR_IA32_XFD register during CPU hotplug events. This can caus...

May 17, 2024
CVE-2021-34976
5.5

CVE-2021-34976 is a use-after-free vulnerability in Foxit PDF Reader's PDF file parsing that allows remote attackers to disclose sensitive information...

May 7, 2024
CVE-2021-34973
5.5

CVE-2021-34973 is a use-after-free vulnerability in Foxit PDF Reader's PDF file parsing that allows attackers to disclose sensitive information. Users...

May 7, 2024
CVE-2023-51610
5.5

This vulnerability in Kofax Power PDF allows attackers to disclose sensitive information by tricking users into opening malicious JP2 files. The flaw ...

May 3, 2024
CVE-2024-30302
5.5

CVE-2024-30302 is a use-after-free vulnerability in Adobe Acrobat Reader that could allow an attacker to read sensitive memory contents and bypass ASL...

May 2, 2024
CVE-2022-37379
5.5

This vulnerability in Foxit PDF Reader allows remote attackers to disclose sensitive information by exploiting improper object validation in the AFSpe...

Mar 29, 2023
CVE-2023-1249
5.5

A use-after-free vulnerability in the Linux kernel's core dump subsystem allows local users to crash the system by triggering a kernel panic. This aff...

Mar 23, 2023
CVE-2026-2804
5.4

A use-after-free vulnerability in Firefox's WebAssembly JavaScript component allows attackers to execute arbitrary code by manipulating freed memory. ...

Feb 24, 2026
CVE-2025-5283
5.4

This CVE describes a use-after-free vulnerability in libvpx (VP8/VP9 video codec library) in Google Chrome. A remote attacker could exploit this via a...

May 27, 2025

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,397 CVEs classified as CWE-416, with 211 rated critical and 2,029 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free