CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,400
Total CVEs
213
Critical
2,030
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
117
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 771
2 Google 402
3 Microsoft 262
4 Debian 241
5 Fedoraproject 209
6 Adobe 147
7 Qualcomm 90
8 Foxit 84
9 Apple 77
10 Mozilla 56

All Use After Free CVEs (2,400)

CVE-2023-1249
5.5

A use-after-free vulnerability in the Linux kernel's core dump subsystem allows local users to crash the system by triggering a kernel panic. This aff...

Mar 23, 2023
CVE-2026-2804
5.4

A use-after-free vulnerability in Firefox's WebAssembly JavaScript component allows attackers to execute arbitrary code by manipulating freed memory. ...

Feb 24, 2026
CVE-2025-5283
5.4

This CVE describes a use-after-free vulnerability in libvpx (VP8/VP9 video codec library) in Google Chrome. A remote attacker could exploit this via a...

May 27, 2025
CVE-2025-0445
5.4

This vulnerability is a use-after-free memory corruption flaw in Chrome's V8 JavaScript engine that could allow an attacker to execute arbitrary code ...

Feb 4, 2025
CVE-2026-26330
5.3

This vulnerability in Envoy proxy allows a crash when both request and response phase rate limits are enabled with apply_on_stream_done configuration....

Mar 10, 2026
CVE-2026-28687
5.3

A heap use-after-free vulnerability in ImageMagick's MSL decoder allows attackers to trigger access to freed memory by crafting malicious MSL files. T...

Mar 10, 2026
CVE-2026-22040
5.3

CVE-2026-22040 is a heap memory corruption vulnerability in NanoMQ MQTT Broker that can be triggered by sending specific traffic patterns, causing the...

Mar 4, 2026
CVE-2026-25983
5.3

This CVE describes a heap-use-after-free vulnerability in ImageMagick's MSL (Magick Scripting Language) parser. Attackers can exploit this by crafting...

Feb 24, 2026
CVE-2025-3212
5.3

A Use After Free vulnerability in Arm GPU kernel drivers allows local non-privileged users to access freed memory through GPU operations. This affects...

Sep 8, 2025
CVE-2024-9979
5.3

CVE-2024-9979 is a use-after-free vulnerability in PyO3, a Rust binding for Python. This flaw allows attackers to potentially cause memory corruption ...

Oct 15, 2024
CVE-2024-6064
5.3

This vulnerability in GPAC's MP4Box tool is a use-after-free flaw in the xmt_node_end function that could allow local attackers to crash the applicati...

Jun 17, 2024
CVE-2025-25177
5.1

This vulnerability allows non-privileged software to make improper GPU system calls that trigger use-after-free kernel exceptions. It affects systems ...

Sep 22, 2025
CVE-2025-6706
5.0

An authenticated MongoDB user can trigger a use-after-free vulnerability by executing specific aggregation pipeline operations, causing server crashes...

Jun 26, 2025
CVE-2025-54101
4.8

A use-after-free vulnerability in Windows SMBv3 Client allows authenticated attackers to execute arbitrary code remotely over a network. This affects ...

Sep 9, 2025
CVE-2026-2408
4.7

A use-after-free vulnerability in Tanium's Cloud Workloads Enforce client extension could allow an attacker to execute arbitrary code or cause a denia...

Feb 20, 2026
CVE-2022-49003
4.7

This CVE describes a use-after-free vulnerability in the Linux kernel's NVMe subsystem when using native multipath. The race condition occurs when con...

Oct 21, 2024
CVE-2022-48869
4.7

A race condition in the Linux kernel's gadgetfs driver allows concurrent mounting and unmounting operations to cause a use-after-free vulnerability. T...

Aug 21, 2024
CVE-2024-43374
4.5

CVE-2024-43374 is a use-after-free vulnerability in Vim's argument list handling that can cause the editor to crash. It affects users running Vim vers...

Aug 16, 2024
CVE-2025-54626
4.4

This CVE describes a use-after-free vulnerability in the cjwindow module where a pointer is not properly cleared after memory is freed. Successful exp...

Aug 6, 2025
CVE-2024-56434
4.4

This CVE describes a use-after-free vulnerability in the device node access module of Huawei devices. Successful exploitation could cause service exce...

Jan 8, 2025
CVE-2024-54030
4.4

This CVE describes a use-after-free vulnerability in OpenHarmony v4.1.2 and earlier versions that allows a local attacker to cause a denial of service...

Jan 7, 2025
CVE-2024-42326
4.4

A use-after-free vulnerability in Zabbix's browser.c es_browser_get_variant function could allow memory corruption. This affects Zabbix installations ...

Nov 27, 2024
CVE-2024-39831
4.4

This CVE describes a use-after-free vulnerability in OpenHarmony v4.1.0 that allows a local attacker with high privileges to execute arbitrary code in...

Oct 8, 2024
CVE-2023-52800
4.4

This CVE addresses a missing RCU read-side critical section in the ath11k WiFi driver's packet logging (pktlog) handling in the Linux kernel. The vuln...

May 21, 2024
CVE-2024-35870
4.4

This CVE describes a use-after-free vulnerability in the Linux kernel's SMB client implementation. When multiple threads access session structures dur...

May 19, 2024
CVE-2025-43536
4.3

A use-after-free vulnerability in Apple's web content processing allows attackers to cause unexpected process crashes by tricking users into visiting ...

Dec 17, 2025
CVE-2025-43368
4.3

A use-after-free vulnerability in Apple Safari, iOS, and iPadOS allows processing malicious web content to cause unexpected crashes. This affects user...

Sep 15, 2025
CVE-2025-0932
4.3

A Use After Free vulnerability in Arm GPU drivers allows non-privileged user processes to access freed memory through GPU operations like WebGL or Web...

Aug 4, 2025
CVE-2025-31239
4.3

A use-after-free vulnerability in Apple operating systems allows parsing malicious files to cause unexpected application termination. This affects use...

May 12, 2025
CVE-2024-27246
4.3

A use-after-free vulnerability in Zoom Workplace Apps and SDKs allows authenticated users to cause denial of service through network access. This affe...

Feb 25, 2025
CVE-2024-27239
4.3

A use-after-free vulnerability in Zoom Workplace Apps and SDKs allows authenticated users to cause denial of service through network access. This affe...

Feb 25, 2025
CVE-2024-7722
4.3

A use-after-free vulnerability in Foxit PDF Reader's Doc object handling allows remote attackers to disclose sensitive information. Attackers can expl...

Aug 21, 2024
CVE-2024-40776
4.3

A use-after-free vulnerability in Apple's WebKit browser engine allows processing malicious web content to cause unexpected process crashes. This affe...

Jul 29, 2024
CVE-2025-20744
4.2

This CVE describes a use-after-free vulnerability in pda (likely a MediaTek component) that allows local privilege escalation. An attacker with System...

Nov 4, 2025
CVE-2025-20745
4.2

This CVE describes a use-after-free memory corruption vulnerability in apusys that could allow local privilege escalation. Attackers who already have ...

Nov 4, 2025
CVE-2025-20743
4.2

This CVE describes a use-after-free vulnerability in clkdbg that could allow local privilege escalation. An attacker who already has System privilege ...

Nov 4, 2025
CVE-2024-41965
4.2

This CVE describes a double-free vulnerability in Vim's dialog_changed() function that occurs when abandoning an unnamed modified buffer. The vulnerab...

Aug 1, 2024
CVE-2026-24914
4.0

A type confusion vulnerability in the camera module could allow attackers to cause denial of service conditions. This affects Huawei consumer devices ...

Feb 6, 2026
CVE-2025-11219
3.1

A use-after-free vulnerability in Chrome's V8 JavaScript engine allows attackers to potentially access out-of-bounds memory via malicious HTML pages. ...

Nov 6, 2025
CVE-2026-24684
N/A

This CVE describes a use-after-free vulnerability in FreeRDP's RDPSND audio channel. When exploited, it could allow remote code execution or denial of...

Feb 9, 2026
CVE-2026-24677
N/A

FreeRDP versions before 3.22.0 contain an out-of-bounds read vulnerability in the H.264 video encoding component. Attackers controlling a malicious RD...

Feb 9, 2026
CVE-2026-24678
N/A

FreeRDP versions before 3.22.0 contain a use-after-free vulnerability in the ecam_channel_write function. This occurs when a capture thread sends samp...

Feb 9, 2026
CVE-2026-24680
N/A

This CVE describes a use-after-free vulnerability in FreeRDP's SDL pointer handling that occurs when memory is freed twice on error conditions. Attack...

Feb 9, 2026
CVE-2026-24681
N/A

This CVE describes a use-after-free vulnerability in FreeRDP's URBDRC channel handling. When Asynchronous bulk transfer completions occur after channe...

Feb 9, 2026
CVE-2026-24683
N/A

This is a use-after-free vulnerability in FreeRDP's ainput_send_input_event function, where improper caching of a channel callback without synchroniza...

Feb 9, 2026
CVE-2026-24491
N/A

FreeRDP versions before 3.22.0 contain a use-after-free vulnerability where video_timer can send client notifications after the control channel is clo...

Feb 9, 2026
CVE-2026-24675
N/A

This CVE describes a use-after-free vulnerability in FreeRDP's USB device handling code. An attacker could exploit this to crash the FreeRDP client or...

Feb 9, 2026
CVE-2026-24676
N/A

This is a use-after-free vulnerability in FreeRDP's audio input handling that occurs during format renegotiation. An attacker could potentially exploi...

Feb 9, 2026
CVE-2025-13845
N/A

A use-after-free vulnerability in Schneider Electric's Rapsody software allows remote code execution when users import malicious SSD project files. Th...

Jan 15, 2026
CVE-2025-65953
N/A

A Heap-Use-After-Free vulnerability in NanoMQ's TCP transport component allows attackers to potentially crash the broker or execute arbitrary code by ...

Nov 25, 2025

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,400 CVEs classified as CWE-416, with 213 rated critical and 2,030 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free