CWE-416
8,661 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,661)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In RGXCreateZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. Us...Show more |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Jul 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Graphics Component Elevation of Privilege Vulnerability |
1Microsoft 3Windows 11 21h2 Windows 11 22h2Windows 11 23h2Jun 17, 2026 Jul 9, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Xbox Wireless Adapter Remote Code Execution Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jul 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Win32k Elevation of Privilege Vulnerability |
1Microsoft 7Windows 10 21h2 Windows 10 22h2Windows 11 21h2+4 moreJun 17, 2026 Jul 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Win32k Elevation of Privilege Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability |
1Microsoft 4Sql Server 2016 Sql Server 2017Sql Server 2019+1 moreJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability |
.NET and Visual Studio Remote Code Execution Vulnerability |
1Microsoft 4Sql Server 2016 Sql Server 2017Sql Server 2019+1 moreJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability |
1Microsoft 4Sql Server 2016 Sql Server 2017Sql Server 2019+1 moreJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability |
1Microsoft 4Sql Server 2016 Sql Server 2017Sql Server 2019+1 moreJun 17, 2026 Jul 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability |
In the Linux kernel, the following vulnerability has been resolved: drm/drm_file: Fix pid refcounting race <maarten.lankhorst@linux.intel.com>, Maxime Ripard <mripard@kernel.org>, Thomas Zimmermann <tzimmermann@suse.de...Show more |
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free. |
Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route hash policy is configured with cookie attributes. Note t...Show more |
1Qualcomm 104Fastconnect 6200 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+101 moreJun 17, 2026 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while handling user packets during VBO bind operation. |
1Qualcomm 220205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+217 moreJun 17, 2026 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. |
@fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended da...Show more |
In the Linux kernel, the following vulnerability has been resolved: 9p: add missing locking around taking dentry fid list Fix a use-after-free on dentry's d_fsdata fid list when a thread looks up a fid through dentry w...Show more |
In the Linux kernel, the following vulnerability has been resolved: genirq/irqdesc: Prevent use-after-free in irq_find_at_or_after() irq_find_at_or_after() dereferences the interrupt descriptor which is returned by mt_...Show more |
1Autodesk 9Advance Steel AutocadAutocad Architecture+6 moreJun 17, 2026 Jun 25, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execut...Show more |