CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,213
Total CVEs
155
Critical
1,903
High
7.9
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 763
2 Google 355
3 Microsoft 258
4 Debian 194
5 Fedoraproject 171
6 Adobe 122
7 Foxit 84
8 Qualcomm 78
9 Apple 62
10 Mozilla 47

All Use After Free CVEs (2,213)

CVE-2024-4770
8.8

A use-after-free vulnerability in Firefox, Firefox ESR, and Thunderbird occurs when saving pages to PDF with certain font styles, potentially causing ...

May 14, 2024
CVE-2024-30006
8.8

This vulnerability in Microsoft's WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending...

May 14, 2024
CVE-2024-4331
8.8

This CVE describes a use-after-free vulnerability in Chrome's Picture-in-Picture feature that allows remote attackers to potentially exploit heap corr...

May 1, 2024
CVE-2024-25648
8.8

A use-after-free vulnerability in Foxit Reader's ComboBox widget handling allows arbitrary code execution when users open malicious PDF files or visit...

Apr 30, 2024
CVE-2024-3834
8.8

This is a use-after-free vulnerability in Google Chrome's Downloads component that allows remote attackers to potentially exploit heap corruption via ...

Apr 17, 2024
CVE-2024-3856
8.8

A use-after-free vulnerability in Firefox's WebAssembly (WASM) garbage collection allows attackers to execute arbitrary code when users visit maliciou...

Apr 16, 2024
CVE-2024-29043
8.8

This vulnerability in Microsoft ODBC Driver for SQL Server allows an attacker to execute arbitrary code on affected systems by sending specially craft...

Apr 9, 2024
CVE-2024-2627
8.8

This is a use-after-free vulnerability in Chrome's Canvas component that allows remote attackers to potentially exploit heap corruption. Attackers can...

Mar 20, 2024
CVE-2024-2176
8.8

This is a use-after-free vulnerability in Chrome's FedCM (Federated Credential Management) component that allows remote attackers to potentially explo...

Mar 6, 2024
CVE-2024-1673
8.8

This vulnerability is a use-after-free flaw in Chrome's Accessibility component that allows a compromised renderer process to potentially exploit heap...

Feb 21, 2024
CVE-2024-21375
8.8

This vulnerability allows remote code execution through the Microsoft WDAC OLE DB provider for SQL Server. An attacker could exploit this to execute a...

Feb 13, 2024
CVE-2024-1077
8.8

This is a use-after-free vulnerability in Google Chrome's Network component that allows remote attackers to potentially exploit heap corruption via ma...

Jan 30, 2024
CVE-2024-1059
8.8

This vulnerability is a use-after-free flaw in Google Chrome's Peer Connection component, allowing remote attackers to potentially exploit stack corru...

Jan 30, 2024
CVE-2024-0806
8.8

This is a use-after-free vulnerability in Google Chrome's password management component that could allow heap corruption. Attackers could potentially ...

Jan 24, 2024
CVE-2024-0224
8.8

This is a use-after-free vulnerability in Chrome's WebAudio component that allows remote attackers to potentially exploit heap corruption via a crafte...

Jan 4, 2024
CVE-2024-0222
8.8

This is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. It allows a remote attacker who has ...

Jan 4, 2024
CVE-2023-6704
8.8

This vulnerability is a use-after-free flaw in the libavif image decoder in Google Chrome. It allows remote attackers to potentially exploit heap corr...

Dec 14, 2023
CVE-2023-6706
8.8

This is a use-after-free vulnerability in Chrome's FedCM (Federated Credential Management) component that allows heap corruption. Attackers can exploi...

Dec 14, 2023
CVE-2023-6508
8.8

This is a use-after-free vulnerability in Google Chrome's Media Stream component that allows remote attackers to potentially exploit heap corruption v...

Dec 6, 2023
CVE-2023-6510
8.8

This is a use-after-free vulnerability in Google Chrome's Media Capture component that could allow heap corruption. Attackers can exploit it by tricki...

Dec 6, 2023
CVE-2023-40088
8.8

This CVE describes a use-after-free vulnerability in Android's Bluetooth stack that could allow remote attackers to execute arbitrary code on affected...

Dec 4, 2023
CVE-2023-6347
8.8

This is a use-after-free vulnerability in Chrome's Mojo IPC system that allows remote attackers to potentially exploit heap corruption. Attackers can ...

Nov 29, 2023
CVE-2023-6350
8.8

This is a use-after-free vulnerability in Chrome's libavif library that allows remote attackers to potentially exploit heap corruption via crafted AVI...

Nov 29, 2023
CVE-2023-6207
8.8

This vulnerability is a use-after-free memory corruption flaw in Firefox, Firefox ESR, and Thunderbird's ReadableByteStreams implementation. It allows...

Nov 21, 2023
CVE-2023-5997
8.8

This is a use-after-free vulnerability in Google Chrome's garbage collection that allows remote attackers to potentially exploit heap corruption. Atta...

Nov 15, 2023
CVE-2023-5996
8.8

This is a use-after-free vulnerability in Chrome's WebAudio component that allows remote attackers to potentially exploit heap corruption. Attackers c...

Nov 8, 2023
CVE-2023-5852
8.8

This is a use-after-free vulnerability in Google Chrome's printing component that allows heap corruption when users perform specific UI gestures. Atta...

Nov 1, 2023
CVE-2023-5854
8.8

This is a use-after-free vulnerability in Google Chrome's Profiles feature that could allow heap corruption. Attackers can exploit it by tricking user...

Nov 1, 2023
CVE-2023-5856
8.8

This is a use-after-free vulnerability in Google Chrome's Side Panel feature that could allow remote attackers to exploit heap corruption. Attackers c...

Nov 1, 2023
CVE-2023-21392
8.8

This CVE describes a use-after-free vulnerability in Android's Bluetooth stack that allows local privilege escalation without user interaction. An att...

Oct 30, 2023
CVE-2023-21361
8.8

This CVE describes a use-after-free vulnerability in Android's Bluetooth stack that allows code execution without user interaction. An attacker could ...

Oct 30, 2023
CVE-2023-41976
8.8

This CVE describes a use-after-free vulnerability in Apple's web content processing components that could allow arbitrary code execution when visiting...

Oct 25, 2023
CVE-2023-5472
8.8

This is a use-after-free vulnerability in Google Chrome's Profiles component that allows remote attackers to potentially exploit heap corruption. Atta...

Oct 25, 2023
CVE-2023-5218
8.8

This critical vulnerability in Google Chrome's Site Isolation feature allows remote attackers to trigger use-after-free conditions via crafted HTML pa...

Oct 11, 2023
CVE-2023-5476
8.8

This is a use-after-free vulnerability in Chrome's Blink History component that allows remote attackers to potentially exploit heap corruption via a c...

Oct 11, 2023
CVE-2023-39928
8.8

A use-after-free vulnerability in WebKitGTK's MediaRecorder API allows memory corruption when processing malicious web content. This could lead to arb...

Oct 6, 2023
CVE-2023-5187
8.8

This is a use-after-free vulnerability in Chrome's extension system that allows heap corruption. Attackers can exploit it by tricking users into insta...

Sep 28, 2023
CVE-2023-39434
8.8

This CVE describes a use-after-free vulnerability in Apple's web content processing components that could allow arbitrary code execution. Attackers co...

Sep 27, 2023
CVE-2023-32541
8.8

A use-after-free vulnerability in Hancom Office 2020 HWord's footerr functionality allows attackers to execute arbitrary code by tricking users into o...

Sep 27, 2023
CVE-2023-4429
8.8

This is a use-after-free vulnerability in Chrome's Loader component that allows remote attackers to potentially exploit heap corruption via a crafted ...

Aug 23, 2023
CVE-2023-36787
8.8

This vulnerability in Microsoft Edge (Chromium-based) allows attackers to gain elevated privileges through a use-after-free memory corruption flaw. It...

Aug 21, 2023
CVE-2023-4366
8.8

This is a use-after-free vulnerability in Google Chrome's extension system that allows heap corruption. Attackers can exploit it by tricking users int...

Aug 15, 2023
CVE-2023-4351
8.8

This is a use-after-free vulnerability in Chrome's Network component that allows remote attackers to potentially exploit heap corruption via a crafted...

Aug 15, 2023
CVE-2023-4349
8.8

This is a use-after-free vulnerability in Google Chrome's Device Trust Connectors that allows remote attackers to potentially exploit heap corruption ...

Aug 15, 2023
CVE-2023-38169
8.8

This vulnerability allows remote code execution on Microsoft SQL Server through the OLE DB provider. Attackers can exploit this to execute arbitrary c...

Aug 8, 2023
CVE-2023-29330
8.8

CVE-2023-29330 is a use-after-free vulnerability in Microsoft Teams that allows remote code execution. Attackers can exploit this by sending specially...

Aug 8, 2023
CVE-2023-4076
8.8

This is a use-after-free vulnerability in Chrome's WebRTC component that allows remote attackers to potentially exploit heap corruption. Attackers cou...

Aug 3, 2023
CVE-2023-4074
8.8

This is a use-after-free vulnerability in Chrome's Blink rendering engine task scheduler that could allow remote attackers to execute arbitrary code o...

Aug 3, 2023
CVE-2023-3728
8.8

This vulnerability is a use-after-free memory corruption flaw in Chrome's WebRTC component that allows remote attackers to potentially execute arbitra...

Aug 1, 2023
CVE-2023-3730
8.8

This is a use-after-free vulnerability in Chrome's Tab Groups feature that allows remote attackers to potentially exploit heap corruption. Attackers c...

Aug 1, 2023

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,213 CVEs classified as CWE-416, with 155 rated critical and 1,903 rated high severity. The average CVSS score for Use After Free vulnerabilities is 7.9.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free