CWE-416
8,642 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,642)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Office Remote Code Execution Vulnerability |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Office Remote Code Execution Vulnerability |
1Microsoft 6Windows 10 20h2 Windows 10 21h2Windows 10 22h2+3 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft DWM Core Library Elevation of Privilege Vulnerability |
1Microsoft 15Windows 10 1607 Windows 10 1809Windows 10 20h2+12 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Win32k Elevation of Privilege Vulnerability |
1Microsoft 15Windows 10 1607 Windows 10 1809Windows 10 20h2+12 moreJun 17, 2026 Jan 10, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Jan 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability |
1Microsoft 15Windows 10 1607 Windows 10 1809Windows 10 20h2+12 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows GDI Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 1809 Windows 10 20h2Windows 10 21h2+5 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
1Microsoft 15Windows 10 1607 Windows 10 1809Windows 10 20h2+12 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 Windows GDI Elevation of Privilege Vulnerability |
A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could be triggered by yanking out a device that is running the gadgetfs side. |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Jan 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial |
Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML p...Show more |
Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML p...Show more |
Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a craft...Show more |
1Qualcomm 78Apq8096au Firmware Ar9380 FirmwareCsr8811 Firmware+75 moreJun 17, 2026 Jan 9, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information exposure in DSP services due to improper handling of freeing memory |
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to heap use-after-free via filters/dmx_m2ts.c:470 in m2tsdmx_declare_pid |
Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrome security severity: High) |
Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security s...Show more |
Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via...Show more |
Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chrome security severity: High) |