CWE-416
8,604 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,604)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Foxitsoftware 2Foxit Reader PhantompdfJun 17, 2026 May 7, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a mali...Show more |
1Qualcomm 457Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+454 moreJun 17, 2026 May 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdra...Show more |
1Qualcomm 396Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+393 moreJun 17, 2026 May 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT...Show more |
1Qualcomm 414Apq8009w Firmware Apq8017 FirmwareApq8053 Firmware+411 moreJun 17, 2026 May 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,...Show more |
1Qualcomm 173Fsm10055 Firmware Fsm10056 FirmwarePm3003a Firmware+170 moreJun 17, 2026 May 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industr...Show more |
3Debian FedoraprojectGetdata Project3Debian Linux FedoraGetdataJun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party...Show more |
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 30, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Debian Fluidsynth2Debian Linux FluidsynthJun 17, 2026 Apr 29, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Apr 26, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Apr 26, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
LeoCAD before 21.03 sometimes allows a use-after-free during the opening of a new document. |
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow...Show more |