CWE-416
8,648 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,648)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU. |
1Microsoft 4365 Apps AccessOffice+1 moreJun 17, 2026 Dec 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Access Remote Code Execution Vulnerability |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Remote Desktop Services Remote Code Execution Vulnerability |
1Microsoft 6Windows Server 2012 Windows Server 2016Windows Server 2019+3 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
1Microsoft 5Windows Server 2016 Windows Server 2019Windows Server 2022+2 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Remote Desktop Services Remote Code Execution Vulnerability |
1Microsoft 5Windows Server 2016 Windows Server 2019Windows Server 2022+2 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Remote Desktop Services Remote Code Execution Vulnerability |
1Microsoft 5Windows Server 2016 Windows Server 2019Windows Server 2022+2 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Remote Desktop Services Remote Code Execution Vulnerability |
1Microsoft 5Windows Server 2016 Windows Server 2019Windows Server 2022+2 moreJun 17, 2026 Dec 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Remote Desktop Services Remote Code Execution Vulnerability |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJun 17, 2026 Dec 12, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Dec 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Input Method Editor (IME) Remote Code Execution Vulnerability |
1Microsoft 4Windows 10 1809 Windows 10 21h2Windows 10 22h2+1 moreJun 17, 2026 Dec 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
1Microsoft 4365 Apps ExcelOffice+1 moreJun 17, 2026 Dec 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Excel Remote Code Execution Vulnerability |
2Gstreamer Gstreamer Project2Gstreamer GstreamerJun 17, 2026 Dec 12, 2024 5.1 MEDIUM· v4 9.1 CRITICAL· v3 N/A· v2 GStreamer is a library for constructing graphs of media-handling components. An Use-After-Free read vulnerability has been discovered affecting the processing of CodecPrivate elements in Matroska streams. In the GST_MATR...Show more |
Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Animate versions 23.0.8, 24.0.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera...Show more |
Photoshop Desktop versions 26.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera...Show more |