CWE-416
7,553 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (7,553)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 4Sql Server 2016 Sql Server 2017Sql Server 2019+1 moreJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability |
1Microsoft 4Sql Server 2016 Sql Server 2017Sql Server 2019+1 moreJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability |
1Microsoft 4Sql Server 2016 Sql Server 2017Sql Server 2019+1 moreJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability |
In the Linux kernel, the following vulnerability has been resolved: drm/drm_file: Fix pid refcounting race <maarten.lankhorst@linux.intel.com>, Maxime Ripard <mripard@kernel.org>, Thomas Zimmermann <tzimmermann@suse.de...Show more |
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free. |
Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route hash policy is configured with cookie attributes. Note t...Show more |
1Qualcomm 104Fastconnect 6200 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+101 moreJun 17, 2026 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while handling user packets during VBO bind operation. |
1Qualcomm 220205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+217 moreJun 17, 2026 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. |
@fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended da...Show more |
In the Linux kernel, the following vulnerability has been resolved: 9p: add missing locking around taking dentry fid list Fix a use-after-free on dentry's d_fsdata fid list when a thread looks up a fid through dentry w...Show more |
In the Linux kernel, the following vulnerability has been resolved: genirq/irqdesc: Prevent use-after-free in irq_find_at_or_after() irq_find_at_or_after() dereferences the interrupt descriptor which is returned by mt_...Show more |
1Autodesk 9Advance Steel AutocadAutocad Architecture+6 moreJun 17, 2026 Jun 25, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execut...Show more |
1Autodesk 9Advance Steel AutocadAutocad Architecture+6 moreJun 17, 2026 Jun 25, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code executio...Show more |
1Autodesk 9Advance Steel AutocadAutocad Architecture+6 moreJun 17, 2026 Jun 25, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or...Show more |
1Autodesk 9Advance Steel AutocadAutocad Architecture+6 moreJun 17, 2026 Jun 25, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along...Show more |
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
In the Linux kernel, the following vulnerability has been resolved: watchdog: cpu5wdt.c: Fix use-after-free bug caused by cpu5wdt_trigger When the cpu5wdt module is removing, the origin code uses del_timer() to de-acti...Show more |