CWE-416
8,604 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,604)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apple 5Ipados Iphone OsMac Os X+2 moreJun 17, 2026 Apr 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPad...Show more |
1Apple 5Ipados Iphone OsMacos+2 moreJun 17, 2026 Apr 2, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A local attacker may be able to elevate their privilege...Show more |
An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-provided function panics. |
1Foxitsoftware 2Foxit Reader PhantompdfJun 17, 2026 Mar 30, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a...Show more |
1Foxitsoftware 2Foxit Reader PhantompdfJun 17, 2026 Mar 30, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a...Show more |
An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_ctx has an invalid value upon re-opening a character device, aka CID-f6bbf0010ba0. |
2Apple Freebsd9Freebsd IcloudIpados+6 moreJun 17, 2026 Mar 26, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large...Show more |
In 11.4-PRERELEASE before r360733 and 11.3-RELEASE before p13, improper mbuf handling in the kernel causes a use-after-free bug by sending IPv6 Hop-by-Hop options over the loopback interface. The use-after-free situation...Show more |
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic. |
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the con...Show more |
1Esri 4Arcgis Engine Arcgis ProArcmap+1 moreJun 17, 2026 Mar 25, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allows an unauthenticated attacker to achieve ar...Show more |
3Debian FedoraprojectQemu3Debian Linux FedoraQemuJun 17, 2026 Mar 23, 2021 N/A· v4 3.2 LOW· v3 2.1 LOW· v2 A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a p...Show more |
2Oracle Sqlite7Communications Network Charging And Control Enterprise Manager For Oracle DatabaseJd Edwards Enterpriseone Tools+4 moreJun 17, 2026 Mar 23, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code exec...Show more |
1Huawei 14Nip6300 Firmware Nip6600 FirmwareNip6800 Firmware+11 moreJun 17, 2026 Mar 22, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause...Show more |
1Qualcomm 401Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+398 moreJun 17, 2026 Mar 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Ind...Show more |
1Qualcomm 328Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+325 moreJun 17, 2026 Mar 17, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IO...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGnutlsJun 17, 2026 Mar 12, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences. |
4Fedoraproject GnuNetapp+1 more5Active Iq Unified Manager E Series Performance AnalyzerEnterprise Linux+2 moreJun 17, 2026 Mar 12, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences. |