CWE-416
8,625 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,625)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this...Show more |
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 May 5, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality in the way a user terminates their session using a simulated Ethernet card and continued usage of t...Show more |
In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch...Show more |
In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch...Show more |
2Qemu Redhat2Enterprise Linux QemuJun 17, 2026 May 2, 2022 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 29, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or sixpack device is detache...Show more |
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion...Show more |
4Debian LinuxNetapp+1 more11Debian Linux Enterprise LinuxH300e Firmware+8 moreJun 17, 2026 Apr 29, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. T...Show more |
heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing denial of service. |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid. |
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, can cause the bounds of a for loop to be miscalculated, which leads to a use after free condition a pointer is...Show more |
3Debian FedoraprojectNothings3Debian Linux FedoraStb Image.hJun 17, 2026 Apr 15, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode. |
nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save(). |
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c. |
2Debian Mariadb2Debian Linux MariadbJun 17, 2026 Apr 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc. |
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c. |
2Debian Mariadb2Debian Linux MariadbJun 17, 2026 Apr 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h. |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Apr 13, 2022 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or...Show more |
2Debian Mariadb2Debian Linux MariadbJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements. |