← Back
CWE-416

8,606 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

JSON object

Loading...

CVEs (8,606)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
67Aqt1000 Firmware
Ar8031 FirmwareAr8035 Firmware+64 more
Jun 17, 2026
Jul 13, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Use after free can occur due to improper handling of response from firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdra...Show more
Use after free can occur due to improper handling of response from firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesShow less
1Autodesk
1Design Review
Jun 17, 2026
Jul 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploit...Show more
A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by remote malicious actors to execute arbitrary code.Show less
1Webkitgtk
1Webkitgtk
Jun 17, 2026
Jul 8, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in remote code execution. The victim needs to...Show more
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in remote code execution. The victim needs to visit a malicious web site to trigger the vulnerability.Show less
3Debian
FedoraprojectWebkitgtk
3Debian Linux
FedoraWebkitgtk
Jun 17, 2026
Jul 8, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A...Show more
A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability.Show less
3Debian
FedoraprojectWebkitgtk
3Debian Linux
FedoraWebkitgtk
Jun 17, 2026
Jul 7, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory c...Show more
A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage.Show less
1Linux
1Acrn
Jun 17, 2026
Jul 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.
1Linux
1Acrn
Jun 17, 2026
Jul 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/pci/virtio/*.c.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Jul 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Jul 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jul 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and user gesture.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Jul 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
4Debian
FedoraprojectNetapp+1 more
8Active Iq Unified Manager
Bootstrap OsDebian Linux+5 more
Jun 17, 2026
Jul 1, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).
2Fedoraproject
Selinux Project
2Fedora
Selinux
Jun 17, 2026
Jul 1, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map).
2Fedoraproject
Selinux Project
2Fedora
Selinux
Jun 17, 2026
Jul 1, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper).
2Tesseract Ocr
Tesseract Ocr Project
2Tesseract Ocr
Tesseract Ocr
Sep 14, 2026
Jul 1, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.
1Keystone Engine
1Keystone Engine
Jun 17, 2026
Jul 1, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken.
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Jun 30, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the device to crash and restart.
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Jun 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause code to execute.
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Jun 30, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the kernel to restart.
1Vector35
1Binary Ninja
Jun 17, 2026
Jun 29, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vector 35 Binary Ninja 2.3.2660 (Build ID 88f343c3). User interaction is required to exploit this vulnerability in that th...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vector 35 Binary Ninja 2.3.2660 (Build ID 88f343c3). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of BNDB files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13670.Show less