CWE-416
8,553 CVEs โข Abstraction: Variant โข Likelihood of Exploit: High
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CVEs (8,553)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Adobe MicrosoftOpensuse+1 more7Edge EvergreenFlash Player+4 moreApr 21, 2026 Feb 2, 2015 N/Aยท v4 9.8 CRITICALยท v3 10.0 HIGHยท v2 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unsp...Show more |
1Adobe 4Air Air SdkAir Sdk & Compiler+1 moreApr 21, 2026 Nov 25, 2014 N/Aยท v4 8.8 HIGHยท v3 10.0 HIGHยท v2 Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler be...Show more |
2Google Redhat5Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+2 moreMay 6, 2026 Oct 8, 2014 N/Aยท v4 N/Aยท v3 7.5 HIGHยท v2 Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. |
2Google Redhat5Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+2 moreMay 6, 2026 Oct 8, 2014 N/Aยท v4 N/Aยท v3 7.5 HIGHยท v2 The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified...Show more |
3Apple GoogleRedhat9Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+6 moreMay 6, 2026 Oct 8, 2014 N/Aยท v4 N/Aยท v3 7.5 HIGHยท v2 Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote...Show more |
2Google Redhat5Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+2 moreMay 6, 2026 Oct 8, 2014 N/Aยท v4 N/Aยท v3 7.5 HIGHยท v2 Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that trigge...Show more |
2Google Redhat5Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+2 moreMay 6, 2026 Oct 8, 2014 N/Aยท v4 N/Aยท v3 7.5 HIGHยท v2 Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash)...Show more |
3Mozilla OpensuseOracle5Evergreen FirefoxOpensuse+2 moreMay 6, 2026 Sep 3, 2014 N/Aยท v4 N/Aยท v3 10.0 HIGHยท v2 Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary c...Show more |
1Microsoft 2Windows Media Center Windows Media Center Tv PackMay 6, 2026 Aug 12, 2014 N/Aยท v4 N/Aยท v3 6.8 MEDIUMยท v2 Use-after-free vulnerability in MCPlayer.dll in Microsoft Windows Media Center TV Pack for Windows Vista, Windows 7 SP1, and Windows Media Center for Windows 8 and 8.1 allows remote attackers to execute arbitrary code vi...Show more |
3Canonical LinuxSuse3Linux Enterprise Server Linux KernelUbuntu LinuxMay 6, 2026 Jul 3, 2014 N/Aยท v4 N/Aยท v3 4.6 MEDIUMยท v2 The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users...Show more |
3Canonical LinuxSuse3Linux Enterprise Server Linux KernelUbuntu LinuxMay 6, 2026 Jul 3, 2014 N/Aยท v4 N/Aยท v3 4.6 MEDIUMยท v2 sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain...Show more |
2Linux Oracle2Linux Linux KernelMay 6, 2026 Jun 23, 2014 N/Aยท v4 5.5 MEDIUMยท v3 4.9 MEDIUMยท v2 The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/Aยท v4 9.8 CRITICALยท v3 7.5 HIGHยท v2 Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/Aยท v4 8.8 HIGHยท v3 9.3 HIGHยท v2 Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote att...Show more |
4Canonical FedoraprojectMozilla+1 more5Fedora FirefoxOpensuse+2 moreMay 6, 2026 Apr 30, 2014 N/Aยท v4 N/Aยท v3 9.3 HIGHยท v2 The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execut...Show more |
1Microsoft 1Internet Explorer Apr 21, 2026 Apr 27, 2014 N/Aยท v4 9.8 CRITICALยท v3 10.0 HIGHยท v2 Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedT...Show more |
Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allows remote attackers to cause a denial of...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 Apr 14, 2014 N/Aยท v4 N/Aยท v3 6.9 MEDIUMยท v2 Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a cr...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Mar 24, 2014 N/Aยท v4 N/Aยท v3 2.9 LOWยท v2 Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the ab...Show more |
3Linux OpensuseSuse3Evergreen Linux Enterprise ServerLinux KernelMay 6, 2026 Mar 24, 2014 N/Aยท v4 N/Aยท v3 2.9 LOWยท v2 Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain...Show more |