← Back
CWE-416

7,455 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

JSON object

Loading...

CVEs (7,455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Android
Jan 14, 2026
Mar 26, 2021
N/A· v4
4.4 MEDIUM· v3
4.9 MEDIUM· v2
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
1Esri
1Arcgis Server
Nov 21, 2024
Mar 25, 2021
N/A· v4
6.8 MEDIUM· v3
6.0 MEDIUM· v2
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the con...Show more
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.Show less
1Esri
4Arcgis Engine
Arcgis ProArcmap+1 more
Nov 21, 2024
Mar 25, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allows an unauthenticated attacker to achieve ar...Show more
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.Show less
3Debian
FedoraprojectQemu
3Debian Linux
FedoraQemu
Nov 21, 2024
Mar 23, 2021
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a p...Show more
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.Show less
2Oracle
Sqlite
7Communications Network Charging And Control
Enterprise Manager For Oracle DatabaseJd Edwards Enterpriseone Tools+4 more
Nov 21, 2024
Mar 23, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code exec...Show more
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.Show less
1Huawei
14Nip6300 Firmware
Nip6600 FirmwareNip6800 Firmware+11 more
Nov 21, 2024
Mar 22, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause...Show more
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2700, S5700, S6700 , S7700, S9700, Secospace USG6300, Secospace USG6500, Secospace USG6600 and USG9500.Show less
1Qualcomm
401Apq8009 Firmware
Apq8009w FirmwareApq8017 Firmware+398 more
Nov 21, 2024
Mar 17, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Ind...Show more
Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesShow less
1Qualcomm
328Apq8009 Firmware
Apq8009w FirmwareApq8017 Firmware+325 more
Nov 21, 2024
Mar 17, 2021
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IO...Show more
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon WearablesShow less
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Oct 24, 2025
Mar 16, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Nov 21, 2024
Mar 16, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
3Fedoraproject
GnuRedhat
3Enterprise Linux
FedoraGnutls
Dec 3, 2025
Mar 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
4Fedoraproject
GnuNetapp+1 more
5Active Iq Unified Manager
E Series Performance AnalyzerEnterprise Linux+2 more
Nov 21, 2024
Mar 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
1Diesel
1Diesel
Nov 21, 2024
Mar 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the diesel crate before 1.4.6 for Rust. There is a use-after-free in the SQLite backend because the semantics of sqlite3_column_name are not followed.
1Synology
1Diskstation Manager
Jan 14, 2025
Mar 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.
1Microsoft
2Windows 10
Windows Server 2016
Nov 21, 2024
Mar 11, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Win32k Elevation of Privilege Vulnerability
1Microsoft
2Edge
Internet Explorer
Oct 30, 2025
Mar 11, 2021
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
Internet Explorer Memory Corruption Vulnerability
1Facebook
1Hhvm
Nov 21, 2024
Mar 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything into it. Otherwise the array might resize, invalidating previously stor...Show more
When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything into it. Otherwise the array might resize, invalidating previously stored references. This pre-reservation was not occurring in HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.Show less
33mf
DebianFedoraproject
3Debian Linux
FedoraLib3mf
Nov 21, 2024
Mar 10, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious...Show more
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Google
1Android
Nov 21, 2024
Mar 10, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...Show more
In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-176919394References: Upstream kernelShow less
1Google
1Android
Nov 21, 2024
Mar 10, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...Show more
In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-170315126Show less