CWE-416— Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.— MITRE CWE catalog
8,874 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-416page 1 of 178
- CVE-2025-24085CRITICALCVSS 10.0EG 10.0⚠ KEV2025-01-27
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A m…
- CVE-2021-22893CRITICALCVSS 10.0EG 10.0⚠ KEV2021-04-23
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated…
- CVE-2024-9680CRITICALCVSS 9.8EG 9.8⚠ KEV2024-10-09
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.…
- CVE-2021-31166CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-11
HTTP Protocol Stack Remote Code Execution Vulnerability
- CVE-2020-3992CRITICALCVSS 9.8EG 9.8⚠ KEV2020-10-20
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 4…
- CVE-2019-0708CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-16
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop …
- CVE-2015-5123CRITICALCVSS 9.8EG 9.8⚠ KEV2015-07-14
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Li…
- CVE-2015-5122CRITICALCVSS 9.8EG 9.8⚠ KEV2015-07-14
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on…
- CVE-2015-5119CRITICALCVSS 9.8EG 9.8⚠ KEV2015-07-08
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remo…
- CVE-2015-0313CRITICALCVSS 9.8EG 9.8⚠ KEV2015-02-02
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as…
- CVE-2014-1776CRITICALCVSS 9.8EG 9.8⚠ KEV2014-04-27
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup func…
- CVE-2016-7892CRITICALCVSS 8.8EG 9.8⚠ KEV2016-12-15
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.
- CVE-2016-0984CRITICALCVSS 8.8EG 9.8⚠ KEV2016-02-10
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK …
- CVE-2014-0496CRITICALCVSS 8.8EG 9.8⚠ KEV2014-01-15
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
- CVE-2018-15982CRITICALCVSS 7.8EG 9.8⚠ KEV2019-01-18
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2018-4878CRITICALCVSS 7.8EG 9.8⚠ KEV2018-02-06
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can l…
- CVE-2024-4671CRITICALCVSS 9.6EG 9.6⚠ KEV2024-05-14
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-26486CRITICALCVSS 9.6EG 9.6⚠ KEV2022-12-22
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.…
- CVE-2021-37973CRITICALCVSS 9.6EG 9.6⚠ KEV2021-10-08
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2021-30633CRITICALCVSS 9.6EG 9.6⚠ KEV2021-10-08
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2020-16017CRITICALCVSS 9.6EG 9.6⚠ KEV2021-01-08
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2026-5281CRITICALCVSS 8.8EG 9.0⚠ KEV2026-04-01
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-2441CRITICALCVSS 8.8EG 9.0⚠ KEV2026-02-13
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-43529CRITICALCVSS 8.8EG 9.0⚠ KEV2025-12-17
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciou…
- CVE-2023-43000CRITICALCVSS 8.8EG 9.0⚠ KEV2025-11-05
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to me…
- CVE-2025-48543CRITICALCVSS 8.8EG 9.0⚠ KEV2025-09-04
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…
- CVE-2023-32373CRITICALCVSS 8.8EG 9.0⚠ KEV2023-06-23
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted we…
- CVE-2023-28205CRITICALCVSS 8.8EG 9.0⚠ KEV2023-04-10
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may le…
- CVE-2023-21674CRITICALCVSS 8.8EG 9.0⚠ KEV2023-01-10
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- CVE-2022-26485CRITICALCVSS 8.8EG 9.0⚠ KEV2022-12-22
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for And…
- CVE-2022-38181CRITICALCVSS 8.8EG 9.0⚠ KEV2022-10-25
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 thro…
- CVE-2022-3038CRITICALCVSS 8.8EG 9.0⚠ KEV2022-09-26
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-0609CRITICALCVSS 8.8EG 9.0⚠ KEV2022-04-05
Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-22620CRITICALCVSS 8.8EG 9.0⚠ KEV2022-03-18
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content …
- CVE-2021-4102CRITICALCVSS 8.8EG 9.0⚠ KEV2022-02-11
Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-37975CRITICALCVSS 8.8EG 9.0⚠ KEV2021-10-08
Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-30661CRITICALCVSS 8.8EG 9.0⚠ KEV2021-09-08
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead…
- CVE-2021-30762CRITICALCVSS 8.8EG 9.0⚠ KEV2021-09-08
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have b…
- CVE-2021-28550CRITICALCVSS 8.8EG 9.0⚠ KEV2021-09-02
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability t…
- CVE-2021-30858CRITICALCVSS 8.8EG 9.0⚠ KEV2021-08-24
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a…
- CVE-2021-30554CRITICALCVSS 8.8EG 9.0⚠ KEV2021-07-02
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-29256CRITICALCVSS 8.8EG 9.0⚠ KEV2021-05-24
. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r2…
- CVE-2021-28664CRITICALCVSS 8.8EG 9.0⚠ KEV2021-05-10
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valh…
- CVE-2021-28663CRITICALCVSS 8.8EG 9.0⚠ KEV2021-05-10
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28…
- CVE-2021-21206CRITICALCVSS 8.8EG 9.0⚠ KEV2021-04-26
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-21193CRITICALCVSS 8.8EG 9.0⚠ KEV2021-03-16
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-26411CRITICALCVSS 8.8EG 9.0⚠ KEV2021-03-11
Internet Explorer Memory Corruption Vulnerability
- CVE-2020-6572CRITICALCVSS 8.8EG 9.0⚠ KEV2021-01-14
Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- CVE-2019-13720CRITICALCVSS 8.8EG 9.0⚠ KEV2019-11-25
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2016-7855CRITICALCVSS 8.8EG 9.0⚠ KEV2016-11-01
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
Map vulnerabilities like CWE-416 to your infrastructure
EchelonGraph correlates every CVE — across CWE-416 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →