CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

8,043 vulnerabilities with CWE-416
CVE-2026-12455 HIGH
Google Chrome - Use After Free
CVSS 7.5
CVE-2026-12452 HIGH
Google Chrome - Use After Free
CVSS 8.8
CVE-2026-12451 HIGH
Google Chrome - Use After Free
CVSS 8.3
CVE-2026-12449 HIGH
Google Chrome - Use After Free
CVSS 7.8
CVE-2026-12445 HIGH
Google Chrome - Use After Free
CVSS 7.5
CVE-2026-12443 HIGH
Google Chrome - Use After Free
CVSS 8.8
CVE-2026-12442 HIGH
Google Chrome - Use After Free
CVSS 8.8
CVE-2026-12441 HIGH
Google Chrome - Use After Free
CVSS 8.8
CVE-2026-12440 CRITICAL
Google Chrome - Use After Free
CVSS 9.6
CVE-2026-12439 HIGH
Google Chrome - Use After Free
CVSS 8.8
CVE-2026-12437 HIGH
Google Chrome - Use After Free
CVSS 8.3
CVE-2026-0143 HIGH
Google Android - Use After Free
CVSS 7.8
CVE-2026-0137 HIGH
Google Android - Use After Free
CVSS 7.8
CVE-2026-0125 HIGH
Google Android - Use After Free
CVSS 7.0
CVE-2026-10640 MEDIUM
Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)
CVSS 4.2
CVE-2026-10639 MEDIUM
Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`
CVSS 4.8
CVE-2026-10638 MEDIUM
Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error
CVSS 5.9
CVE-2026-10637 MEDIUM
Use-after-free of net_pkt in IPv6 MLD send path triggerable by a link-local MLD Query
CVSS 5.9
CVE-2026-10636 LOW
Use-after-free in Zephyr IPv4 IGMP send path (igmp_send)
CVSS 3.7
CVE-2026-12329 MEDIUM
Memory safety bug fixed in Thunderbird ESR 140.12
CVSS 5.3
CVE-2026-12314 HIGH
Mozilla Firefox - Memory Safety Bug Fixed in Thunderbird 152
CVSS 7.5
CVE-2026-12310 HIGH
Mozilla Firefox - Memory Safety Bug Fixed in Thunderbird 152
CVSS 7.5
CVE-2026-12298 MEDIUM
Mozilla Firefox - Memory Safety Bug Fixed in Thunderbird 152
CVSS 5.4
CVE-2026-12293 CRITICAL
Use-after-free in the Graphics: WebGPU component
CVSS 9.8
CVE-2026-12291 HIGH
Use-after-free in the Networking: HTTP component
CVSS 8.8
Details
Vulnerabilities 8,043
Exploit Likelihood High