CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,214
Total CVEs
156
Critical
1,903
High
7.9
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 763
2 Google 356
3 Microsoft 258
4 Debian 194
5 Fedoraproject 171
6 Adobe 122
7 Foxit 84
8 Qualcomm 78
9 Apple 62
10 Mozilla 47

All Use After Free CVEs (2,214)

CVE-2022-0302
8.8

This is a use-after-free vulnerability in Google Chrome's Omnibox (address bar) that allows an attacker to potentially exploit heap corruption. Attack...

Feb 12, 2022
CVE-2022-0308
8.8

This is a use-after-free vulnerability in Google Chrome's Data Transfer component on Chrome OS that allows remote attackers to potentially exploit hea...

Feb 12, 2022
CVE-2022-0289
8.8

This vulnerability allows remote attackers to potentially exploit heap corruption via a crafted HTML page due to a use-after-free bug in Chrome's Safe...

Feb 12, 2022
CVE-2022-0099
8.8

This is a use-after-free vulnerability in Google Chrome's sign-in functionality that allows heap corruption when a user performs specific gestures. At...

Feb 12, 2022
CVE-2022-0103
8.8

This vulnerability is a use-after-free memory corruption flaw in SwiftShader, a software rendering component of Google Chrome. It allows remote attack...

Feb 12, 2022
CVE-2022-0105
8.8

This is a use-after-free vulnerability in Google Chrome's PDF accessibility features that allows remote attackers to potentially exploit heap corrupti...

Feb 12, 2022
CVE-2022-0107
8.8

This is a use-after-free vulnerability in Chrome OS's File Manager API that allows heap corruption. Attackers can exploit it by convincing users to in...

Feb 12, 2022
CVE-2021-4102
8.8

This vulnerability is a use-after-free memory corruption flaw in Chrome's V8 JavaScript engine that allows remote attackers to potentially execute arb...

Feb 11, 2022
CVE-2021-4154
8.8

A use-after-free vulnerability in the Linux kernel's cgroup v1 parser allows local attackers with user privileges to escalate privileges. This can lea...

Feb 4, 2022
CVE-2021-40420
8.8

A use-after-free vulnerability in Foxit PDF Reader's JavaScript engine allows arbitrary code execution when a user opens a malicious PDF file or visit...

Feb 4, 2022
CVE-2021-46242
8.8

CVE-2021-46242 is a heap-use-after-free vulnerability in HDF5 library's H5AC_unpin_entry component that could allow attackers to execute arbitrary cod...

Jan 21, 2022
CVE-2021-4063
8.8

This is a use-after-free vulnerability in Chrome's developer tools that allows remote attackers to potentially exploit heap corruption via a crafted H...

Dec 23, 2021
CVE-2021-4065
8.8

This vulnerability is a use-after-free memory corruption flaw in Chrome's autofill feature that allows attackers to potentially execute arbitrary code...

Dec 23, 2021
CVE-2021-4067
8.8

This is a use-after-free vulnerability in ChromeOS's window manager that allows remote attackers to potentially exploit heap corruption via a crafted ...

Dec 23, 2021
CVE-2021-4052
8.8

This is a use-after-free vulnerability in Google Chrome's web app component that allows heap corruption. Attackers can exploit it by tricking users in...

Dec 23, 2021
CVE-2021-4057
8.8

This is a use-after-free vulnerability in Chrome's file API that allows a remote attacker who has already compromised the renderer process to potentia...

Dec 23, 2021
CVE-2021-38011
8.8

This is a use-after-free vulnerability in Chrome's storage foundation that allows remote attackers to potentially exploit heap corruption via crafted ...

Dec 23, 2021
CVE-2021-38005
8.8

This is a use-after-free vulnerability in Chrome's loader component that allows remote attackers to potentially exploit heap corruption via a crafted ...

Dec 23, 2021
CVE-2021-43539
8.8

A use-after-free vulnerability in Mozilla's WebAssembly (wasm) implementation could allow an attacker to cause memory corruption and potentially execu...

Dec 8, 2021
CVE-2021-37997
8.8

This is a use-after-free vulnerability in Google Chrome's sign-in functionality that allows remote attackers to potentially exploit heap corruption. A...

Nov 23, 2021
CVE-2021-21900
8.8

This CVE describes a use-after-free vulnerability in LibreCAD's libdxfrw library that allows remote code execution. Attackers can exploit it by tricki...

Nov 19, 2021
CVE-2021-37983
8.8

This is a use-after-free vulnerability in Chrome's Dev Tools that allows remote attackers to potentially exploit heap corruption. Attackers can craft ...

Nov 2, 2021
CVE-2021-37985
8.8

This is a use-after-free vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to potentially exploit heap corruption. Attackers...

Nov 2, 2021
CVE-2021-37987
8.8

This is a use-after-free vulnerability in Chrome's Network APIs that allows remote attackers to potentially exploit heap corruption via a crafted HTML...

Nov 2, 2021
CVE-2021-37993
8.8

This is a use-after-free vulnerability in Google Chrome's PDF accessibility features that allows remote attackers to potentially exploit heap corrupti...

Nov 2, 2021
CVE-2021-37977
8.8

This is a use-after-free vulnerability in Chrome's garbage collection that allows remote attackers to potentially exploit heap corruption. Attackers c...

Nov 2, 2021
CVE-2021-30809
8.8

CVE-2021-30809 is a use-after-free vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web c...

Oct 28, 2021
CVE-2021-37975
8.8

This is a use-after-free vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to potentially exploit heap corruption. Attackers...

Oct 8, 2021
CVE-2021-37956
8.8

This is a use-after-free vulnerability in Google Chrome for Android that allows a remote attacker who has already compromised the renderer process to ...

Oct 8, 2021
CVE-2021-37959
8.8

This is a use-after-free vulnerability in Google Chrome's Task Manager that allows an attacker to potentially exploit heap corruption. Attackers can t...

Oct 8, 2021
CVE-2021-37962
8.8

This is a use-after-free vulnerability in Chrome's Performance Manager component that allows a remote attacker who has already compromised the rendere...

Oct 8, 2021
CVE-2021-30625
8.8

This is a use-after-free vulnerability in Chrome's Selection API that allows remote attackers to potentially exploit heap corruption. Attackers can tr...

Oct 8, 2021
CVE-2021-30629
8.8

This is a use-after-free vulnerability in Google Chrome's permissions system that allows a remote attacker who has already compromised the renderer pr...

Oct 8, 2021
CVE-2021-1876
8.8

This is a use-after-free vulnerability in macOS that allows arbitrary code execution when processing malicious web content. Attackers can exploit this...

Sep 8, 2021
CVE-2021-30802
8.8

This is a use-after-free vulnerability in iOS and tvOS WebKit that allows arbitrary code execution when processing malicious web content. Attackers ca...

Sep 8, 2021
CVE-2021-30762
8.8

CVE-2021-30762 is a use-after-free vulnerability in iOS that allows arbitrary code execution when processing malicious web content. Attackers can expl...

Sep 8, 2021
CVE-2021-30624
8.8

CVE-2021-30624 is a use-after-free vulnerability in Chromium's Autofill feature that allows attackers to execute arbitrary code or cause a denial of s...

Sep 3, 2021
CVE-2021-30606
8.8

CVE-2021-30606 is a use-after-free vulnerability in Chromium's Blink rendering engine that allows remote attackers to execute arbitrary code or cause ...

Sep 3, 2021
CVE-2021-30608
8.8

CVE-2021-30608 is a use-after-free vulnerability in Chromium's Web Share API that allows remote attackers to execute arbitrary code or cause a denial ...

Sep 3, 2021
CVE-2021-30610
8.8

This vulnerability is a use-after-free flaw in Chromium's Extensions API that allows remote attackers to execute arbitrary code or cause a denial of s...

Sep 3, 2021
CVE-2021-30612
8.8

CVE-2021-30612 is a use-after-free vulnerability in WebRTC component of Chromium-based browsers. It allows remote attackers to execute arbitrary code ...

Sep 3, 2021
CVE-2021-30616
8.8

CVE-2021-30616 is a use-after-free vulnerability in Chromium's media component that allows remote attackers to execute arbitrary code or cause denial ...

Sep 3, 2021
CVE-2021-30622
8.8

This vulnerability is a use-after-free flaw in Chromium's WebApp installation component that allows attackers to execute arbitrary code or cause a den...

Sep 3, 2021
CVE-2021-28550
8.8

CVE-2021-28550 is a use-after-free vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF fil...

Sep 2, 2021
CVE-2021-30600
8.8

This is a use-after-free vulnerability in Google Chrome's printing component that allows heap corruption. Attackers who have already compromised the r...

Aug 26, 2021
CVE-2021-30602
8.8

This is a use-after-free vulnerability in Chrome's WebRTC component that allows heap corruption. Attackers can exploit it by tricking users into visit...

Aug 26, 2021
CVE-2021-30604
8.8

This is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome that allows heap corruption. Attacker...

Aug 26, 2021
CVE-2021-30951
8.8

This is a use-after-free vulnerability in Apple's WebKit browser engine that could allow arbitrary code execution when processing malicious web conten...

Aug 24, 2021
CVE-2021-30858
8.8

This is a use-after-free vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content. It...

Aug 24, 2021
CVE-2020-21688
8.8

CVE-2020-21688 is a heap-use-after-free vulnerability in FFmpeg's memory management function that allows attackers to execute arbitrary code on affect...

Aug 10, 2021

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,214 CVEs classified as CWE-416, with 156 rated critical and 1,903 rated high severity. The average CVSS score for Use After Free vulnerabilities is 7.9.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free