CWE-416
7,934 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (7,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium secu...Show more |
Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium...Show more |
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (...Show more |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 17, 2026 Jul 14, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. |
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 21h2+8 moreJul 17, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 17, 2026 Jul 14, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
1Microsoft 7Windows 10 21h2 Windows 10 22h2Windows 11 24h2+4 moreJul 17, 2026 Jul 14, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 21h2+8 moreJul 16, 2026 Jul 14, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
1Microsoft 9Windows 10 1809 Windows 10 21h2Windows 10 22h2+6 moreJul 16, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJul 16, 2026 Jul 14, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJul 16, 2026 Jul 14, 2026 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack. |
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 20, 2026 Jul 14, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 22, 2026 Jul 14, 2026 N/A· v4 9.9 CRITICAL· v3 N/A· v2 Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 23, 2026 Jul 14, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 22, 2026 Jul 14, 2026 N/A· v4 8.1 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network. |