CWE-416— Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.— MITRE CWE catalog
8,874 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-416page 2 of 178
- CVE-2015-2360CRITICALCVSS 8.8EG 9.0⚠ KEV2015-06-10
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8…
- CVE-2014-8439CRITICALCVSS 8.8EG 9.0⚠ KEV2014-11-25
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 all…
- CVE-2014-0322CRITICALCVSS 8.8EG 9.0⚠ KEV2014-02-14
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as explo…
- CVE-2013-3897CRITICALCVSS 8.8EG 9.0⚠ KEV2013-10-09
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript c…
- CVE-2013-3893CRITICALCVSS 8.8EG 9.0⚠ KEV2013-09-18
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-…
- CVE-2013-1347CRITICALCVSS 8.8EG 9.0⚠ KEV2013-05-05
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May…
- CVE-2013-2551CRITICALCVSS 8.8EG 9.0⚠ KEV2013-03-11
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competiti…
- CVE-2012-4792CRITICALCVSS 8.8EG 9.0⚠ KEV2012-12-30
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as de…
- CVE-2010-0806CRITICALCVSS 8.8EG 9.0⚠ KEV2010-03-10
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the dele…
- CVE-2010-0249CRITICALCVSS 8.8EG 9.0⚠ KEV2010-01-15
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 all…
- CVE-2023-33106CRITICALCVSS 8.4EG 9.0⚠ KEV2023-12-05
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
- CVE-2022-22071CRITICALCVSS 8.4EG 9.0⚠ KEV2022-06-14
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IO…
- CVE-2021-1905CRITICALCVSS 8.4EG 9.0⚠ KEV2021-05-07
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile…
- CVE-2020-6819CRITICALCVSS 8.1EG 9.0⚠ KEV2020-04-24
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.…
- CVE-2012-4969CRITICALCVSS 8.1EG 9.0⚠ KEV2012-09-18
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
- CVE-2010-3962CRITICALCVSS 8.1EG 9.0⚠ KEV2010-11-05
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag refe…
- CVE-2023-0266CRITICALCVSS 7.9EG 9.0⚠ KEV2023-01-30
A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access f…
- CVE-2025-62221CRITICALCVSS 7.8EG 9.0⚠ KEV2025-12-09
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-32709CRITICALCVSS 7.8EG 9.0⚠ KEV2025-05-13
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2025-32701CRITICALCVSS 7.8EG 9.0⚠ KEV2025-05-13
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-30400CRITICALCVSS 7.8EG 9.0⚠ KEV2025-05-13
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
- CVE-2025-29824CRITICALCVSS 7.8EG 9.0⚠ KEV2025-04-08
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-21335CRITICALCVSS 7.8EG 9.0⚠ KEV2025-01-14
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
- CVE-2025-21334CRITICALCVSS 7.8EG 9.0⚠ KEV2025-01-14
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
- CVE-2024-43047CRITICALCVSS 7.8EG 9.0⚠ KEV2024-10-07
Memory corruption while maintaining memory maps of HLOS memory.
- CVE-2024-38193CRITICALCVSS 7.8EG 9.0⚠ KEV2024-08-13
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2024-38107CRITICALCVSS 7.8EG 9.0⚠ KEV2024-08-13
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
- CVE-2024-36971CRITICALCVSS 7.8EG 9.0⚠ KEV2024-06-10
In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules a…
- CVE-2024-4610CRITICALCVSS 7.8EG 9.0⚠ KEV2024-06-07
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue aff…
- CVE-2024-1086CRITICALCVSS 7.8EG 9.0⚠ KEV2024-01-31
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, an…
- CVE-2023-41974CRITICALCVSS 7.8EG 9.0⚠ KEV2024-01-10
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-2586CRITICALCVSS 7.8EG 9.0⚠ KEV2024-01-08
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
- CVE-2023-33063CRITICALCVSS 7.8EG 9.0⚠ KEV2023-12-05
Memory corruption in DSP Services during a remote call from HLOS to DSP.
- CVE-2023-36802CRITICALCVSS 7.8EG 9.0⚠ KEV2023-09-12
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
- CVE-2023-29336CRITICALCVSS 7.8EG 9.0⚠ KEV2023-05-09
Win32k Elevation of Privilege Vulnerability
- CVE-2023-21608CRITICALCVSS 7.8EG 9.0⚠ KEV2023-01-18
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current …
- CVE-2021-1048CRITICALCVSS 7.8EG 9.0⚠ KEV2021-12-15
In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex…
- CVE-2021-40449CRITICALCVSS 7.8EG 9.0⚠ KEV2021-10-13
Win32k Elevation of Privilege Vulnerability
- CVE-2021-34486CRITICALCVSS 7.8EG 9.0⚠ KEV2021-08-12
Windows Event Tracing Elevation of Privilege Vulnerability
- CVE-2020-9715CRITICALCVSS 7.8EG 9.0⚠ KEV2020-08-19
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .
- CVE-2019-8605CRITICALCVSS 7.8EG 9.0⚠ KEV2019-12-18
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
- CVE-2019-8526CRITICALCVSS 7.8EG 9.0⚠ KEV2019-12-18
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.
- CVE-2019-2215CRITICALCVSS 7.8EG 9.0⚠ KEV2019-10-11
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious …
- CVE-2019-0211CRITICALCVSS 7.8EG 9.0⚠ KEV2019-04-08
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrar…
- CVE-2017-0263CRITICALCVSS 7.8EG 9.0⚠ KEV2017-05-12
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain priv…
- CVE-2017-0261CRITICALCVSS 7.8EG 9.0⚠ KEV2017-05-12
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique f…
- CVE-2009-4324CRITICALCVSS 7.8EG 9.0⚠ KEV2009-12-15
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF fi…
- CVE-2025-27038CRITICALCVSS 7.5EG 9.0⚠ KEV2025-06-03
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
- CVE-2020-0674CRITICALCVSS 7.5EG 9.0⚠ KEV2020-02-11
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-07…
- CVE-2019-1429CRITICALCVSS 7.5EG 9.0⚠ KEV2019-11-12
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-14…
Map vulnerabilities like CWE-416 to your infrastructure
EchelonGraph correlates every CVE — across CWE-416 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →