← Back
CWE-416

7,456 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

JSON object

Loading...

CVEs (7,456)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x79732. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x5166d. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via SortSubCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ArgTypeCheck in src/jsiFunc.c. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueCopyMove in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_wswebsocketObjFree in src/jsiWebSocket.c. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_UserObjDelete in src/jsiUserObj.c. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_ObjFree in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via DeleteTreeValue in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueLookupBase in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_DecrRefCount in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).
1Jsish
1Jsish
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_IncrRefCount in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).
1Hdfgroup
1Hdf5
Jun 17, 2026
Jan 21, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
1Gpac
1Gpac
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at utils/alloc.c. This vulnerability can lead to a Denial of Service (DoS).
1Nvidia
1Shield Experience
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit a use-after-free condition, leading to code privilege escalation, loss of confidentiality and integ...Show more
NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit a use-after-free condition, leading to code privilege escalation, loss of confidentiality and integrity, or denial of service.Show less
4Debian
LinuxNetapp+1 more
15Communications Cloud Native Core Binding Support Function
Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+12 more
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition....Show more
A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This flaw affects Linux kernel versions prior to 5.16-rc4.Show less
1Jerryscript
1Jerryscript
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in JerryScript commit a6ab5e9. There is an Use-After-Free in lexer_compare_identifier_to_string in js-lexer.c file.
1Modex Project
1Modex
Jun 17, 2026
Jan 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Modex v2.11 was discovered to contain an Use-After-Free vulnerability via the component tcache.
2Fedoraproject
Gnu
2Fedora
Recutils
Jun 17, 2026
Jan 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
2Fedoraproject
Gnu
2Fedora
Recutils
Jun 17, 2026
Jan 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.