CWE-416
8,588 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,588)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adobe 2Acrobat Dc Acrobat Reader DcJun 17, 2026 May 22, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use afte...Show more |
An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to bypass the detection engine. |
GoHTTP through 2017-07-25 has a sendHeader use-after-free. |
3Huawei MicrosoftSiemens67Agile Controller Campus Firmware Aptio FirmwareAtellica Solution Firmware+64 moreJun 17, 2026 May 16, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, a...Show more |
The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability. |
2Canonical Sqlite2Sqlite Ubuntu LinuxJun 17, 2026 May 10, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code ex...Show more |
In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...Show more |
In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the Bluetooth service with no additional exe...Show more |
5Canonical DebianLinux+2 more14Active Iq Unified Manager Cn1610 FirmwareDebian Linux+11 moreJun 17, 2026 May 8, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup. |
3Linux OpensuseRedhat9Enterprise Linux Enterprise Linux AusEnterprise Linux Desktop+6 moreJun 17, 2026 May 7, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si module is removed, related to drivers/char/ipmi/ipmi_si_intf.c, drivers/ch...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 May 7, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a De...Show more |
6Canonical DebianF5+3 more13Active Iq Unified Manager Debian LinuxHci Compute Node+10 moreNov 21, 2024 May 7, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. |
1Qualcomm 21Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+18 moreNov 21, 2024 May 6, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A Use After Free Condition can occur in Thermal Engine in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 450, SD 615/16/SD 41...Show more |
1Qualcomm 12Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+9 moreNov 21, 2024 May 6, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 While processing camera buffers in camera driver, a use after free condition can occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 625, S...Show more |
A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the rem...Show more |
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. Thi...Show more |
A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a po...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Apr 23, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/lin...Show more |
libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images. |
In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. P...Show more |