CWE-416
8,606 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,606)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 360Apq8009w Firmware Apq8017 FirmwareApq8053 Firmware+357 moreJun 17, 2026 Jun 9, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Sna...Show more |
1Qualcomm 406Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+403 moreJun 17, 2026 Jun 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Use after free issue when importing a DMA buffer by using the CPU address of the buffer due to attachment is not cleaned up properly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had compromised the renderer process of a user who had saved a credit card in their Google account to po...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Jun 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_func and ctx reference holding, aka CID-6d816e088c35. |
2Linux Netapp22Aff 8300 Firmware Aff 8700 FirmwareAff A400 Firmware+19 moreJun 17, 2026 Jun 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46. |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreNov 21, 2024 Jun 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8. |
3Linux NetappStarwindsoftware11H300e Firmware H300s FirmwareH410c Firmware+8 moreJun 17, 2026 Jun 7, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 4, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 4, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 4, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 4, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 4, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. |