CWE-416
8,652 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,652)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c. |
3Debian LinuxNetapp3Debian Linux Hci Baseboard Management ControllerLinux KernelJun 17, 2026 Jun 9, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel...Show more |
A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data...Show more |
CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c. |
Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process.
|
1Hornerautomation 2Cscape Cscape EnvisionrvJun 17, 2026 Jun 6, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerabi...Show more |
2Google Linuxfoundation3Android Iot YoctoYoctoJun 17, 2026 Jun 6, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In vcu, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07...Show more |
1Qualcomm 49Aqt1000 Firmware Qam8255p FirmwareQca6420 Firmware+46 moreJun 17, 2026 Jun 6, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption due to use after free in Core when multiple DCI clients register and deregister. |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 Jun 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defra...Show more |
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Foc...Show more |
1Mozilla 5Firefox Firefox EsrFirefox Mobile+2 moreAug 19, 2026 Jun 2, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability aff...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Jun 2, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. This vulnerability affects Firefox < 110, Thunderbird < 102.8,...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Jun 2, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability aff...Show more |
1Arm 2Avalon Gpu Kernel Driver Valhall Gpu Kernel DriverJun 17, 2026 Jun 2, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0,...Show more |
A use after free flaw was found in hfsplus_put_super in fs/hfsplus/super.c in the Linux Kernel. This flaw could allow a local user to cause a denial of service problem. |
2Linux Netapp2Hci Baseboard Management Controller Linux KernelJun 17, 2026 Jun 1, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This f...Show more |
Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) |
Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) |
Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) |
Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium sec...Show more |