CWE-416
7,270 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (7,270)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apple CanonicalGoogle+1 more5Chrome Iphone OsSafari+2 moreApr 29, 2026 Sep 7, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause...Show more |
Use-after-free vulnerability in the Notifications presenter in Google Chrome before 6.0.472.53 allows attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. |
4Apple CanonicalGoogle+1 more5Chrome Iphone OsSafari+2 moreApr 29, 2026 Aug 24, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary co...Show more |
3Debian FedoraprojectGnupg3Debian Linux FedoraGnupgApr 29, 2026 Aug 5, 2010 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large numbe...Show more |
3Mozilla OpensuseSuse7Firefox Linux Enterprise DesktopLinux Enterprise Server+4 moreApr 29, 2026 Jul 30, 2010 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a la...Show more |
Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute...Show more |
3Google OpensuseSuse4Chrome OpensuseSuse Linux Enterprise Desktop+1 moreApr 29, 2026 Jun 15, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remot...Show more |
Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to execute arbitrary code or cause a denial of...Show more |
4Debian LinuxOpensuse+1 more6Debian Linux Linux Enterprise DesktopLinux Enterprise High Availability Extension+3 moreApr 29, 2026 May 7, 2010 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly h...Show more |
5Canonical FedoraprojectMit+2 more5Fedora Kerberos 5Linux Enterprise+2 moreApr 29, 2026 Apr 7, 2010 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a ka...Show more |
4Apple CanonicalFedoraproject+1 more5Fedora Iphone OsOpensuse+2 moreApr 29, 2026 Mar 15, 2010 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags. |
1Microsoft 7Internet Explorer Windows 2000Windows 2003 Server+4 moreMay 21, 2026 Mar 10, 2010 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid poi...Show more |
4Apple CanonicalFedoraproject+1 more10Cups Enterprise LinuxEnterprise Linux Desktop+7 moreApr 29, 2026 Mar 5, 2010 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows rem...Show more |
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is de...Show more |
Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP2 and SP3, allows remote attackers to execute arbitrary code by unloading a Flash object that is currently being accesse...Show more |
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2...Show more |
3Adobe OpensuseSuse5Acrobat Acrobat ReaderLinux Enterprise+2 moreApr 21, 2026 Dec 15, 2009 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code v...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Dec 9, 2009 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to...Show more |
5Apple CanonicalDebian+2 more7Cups Debian LinuxEnterprise Linux+4 moreApr 23, 2026 Nov 20, 2009 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a de...Show more |
2Qemu Redhat3Enterprise Linux Server Enterprise Linux WorkstationQemuApr 23, 2026 Oct 23, 2009 N/A· v4 9.9 CRITICAL· v3 8.5 HIGH· v2 Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1...Show more |