CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,457 vulnerabilities with CWE-416
CVE-2026-8514 HIGH
Google Chrome < 148.0.7778.168 - Use-After-Free in Aura
CVSS 8.3
CVE-2026-8513 HIGH
Google Chrome < 148.0.7778.168 - Use-After-Free in Input
CVSS 8.3
CVE-2026-8512 HIGH
Google Chrome < 148.0.7778.168 - Use-After-Free in FileSystem
CVSS 8.3
CVE-2026-8511 CRITICAL
Google Chrome < 148.0.7778.168 - Use-After-Free in UI via Crafted HTML Page
CVSS 9.6
CVE-2026-41218 HIGH
F5 BIG-IP PEM iRules - TMM Denial of Service
CVSS 7.5
CVE-2026-40701 MEDIUM
NGINX Plus and NGINX Open Source - Use-After-Free in ngx_http_ssl_module
CVSS 4.8
CVE-2026-8336 HIGH
Post-authentication use-after-free error in $_internalJsEmit and mapreduce commands
CVSS 7.5
CVE-2026-8201 MEDIUM
Use-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted Fields
CVSS 6.4
CVE-2026-45185 CRITICAL
Exim 4.97-4.99.2 - Unauthenticated Use-After-Free via TLS Close Notify During CHUNKING Transfer
CVSS 9.8
CVE-2026-42825 HIGH
Microsoft Windows 10 Version 1607 - Windows Telephony Service Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-41095 HIGH
Microsoft Windows Server 2012 R2 - Data Deduplication Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40419 HIGH
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40418 HIGH
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40415 HIGH
Microsoft Windows TCP/IP - Use-After-Free Remote Code Execution
CVSS 8.1
CVE-2026-40410 HIGH
Microsoft Windows 10 Version 1607 - Windows SMB Client Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-40408 HIGH
Microsoft Windows 10 Version 1607 - Windows WAN ARP Driver Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40406 HIGH
Microsoft Windows TCP/IP - Use-After-Free Information Disclosure
CVSS 7.5
CVE-2026-40402 CRITICAL
Microsoft Windows 11 version 22H3 - Windows Hyper-V Elevation of Privilege Vulnerability
CVSS 9.3
CVE-2026-40382 HIGH
Microsoft Windows 10 Version 1607 - Windows Telephony Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40366 HIGH
Microsoft Word Remote Code Execution Vulnerability
CVSS 8.4
CVE-2026-40361 HIGH
Microsoft Word Remote Code Execution Vulnerability
CVSS 8.4
CVE-2026-40359 HIGH
Microsoft Excel Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-40358 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVSS 8.4
CVE-2026-35418 HIGH
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-35416 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS 7.0
Details
Vulnerabilities 7,457
Exploit Likelihood High