← Back
CWE-416

8,553 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

JSON object

Loading...

CVEs (8,553)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
2Flash Player
Flash Player Desktop Runtime
May 13, 2026
Feb 15, 2017
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful exploitation could lead to arbitrary code execution.
1Adobe
2Flash Player
Flash Player Desktop Runtime
May 13, 2026
Feb 15, 2017
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in a routine related to player shutdown. Successful exploitation could lead to arbitrary code execution.
4Debian
MariadbOracle+1 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
May 13, 2026
Feb 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3.
2Gstreamer
Gstreamer Project
2Gstreamer
Gstreamer
May 13, 2026
Feb 9, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial...Show more
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.Show less
2Google
Linux
2Android
Linux Kernel
May 13, 2026
Feb 8, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibili...Show more
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32401526. References: N-CVE-2017-0428.Show less
2Google
Linux
2Android
Linux Kernel
May 13, 2026
Feb 7, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect...Show more
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.Show less
1Linux
1Linux Kernel
May 13, 2026
Feb 6, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or possibly gain privileges...Show more
Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or possibly gain privileges via crafted ioctl calls on the /dev/kvm device.Show less
1Ibm
1Bigfix Platform
May 13, 2026
Feb 1, 2017
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker could exploit this vulnerability to execute arbitrary code on the system.
3Canonical
Libical ProjectRedhat
8Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+5 more
May 13, 2026
Jan 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
1Libical Project
1Libical
May 13, 2026
Jan 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The icalproperty_new_clone function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
3Debian
GnuRedhat
8Bash
Debian LinuxEnterprise Linux Desktop+5 more
May 13, 2026
Jan 23, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
1Giflib Project
1Giflib
May 13, 2026
Jan 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.
1Google
1Chrome
May 13, 2026
Jan 19, 2017
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
A heap use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1Google
1Chrome
May 13, 2026
Jan 19, 2017
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
1Google
1Chrome
May 13, 2026
Jan 19, 2017
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
A use after free in webaudio in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
1Google
1Chrome
May 13, 2026
Jan 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1Google
1Chrome
May 13, 2026
Jan 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
1Google
1Chrome
May 13, 2026
Jan 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
1Citrix
1Provisioning Services
May 13, 2026
Jan 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
1Libical Project
1Libical
May 13, 2026
Jan 18, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file.