CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,483 vulnerabilities with CWE-416
CVE-2026-4684 HIGH
Race condition, use-after-free in the Graphics: WebRender component
CVSS 7.5
CVE-2026-4752 MEDIUM
Use After Free in No-Chicken Echo-Mate
CVSS 6.4
CVE-2026-4737 HIGH
Use-After-Free Vulnerability in No-Chicken/Echo-Mate
CVE-2026-4680 HIGH
Google Chrome < 146.0.7680.165 - Use-After-Free in FedCM
CVSS 8.8
CVE-2026-4678 HIGH
Google Chrome < 146.0.7680.165 - Use-After-Free in WebGPU
CVSS 8.8
CVE-2026-4676 HIGH
Google Chrome < 146.0.7680.165 - Use-After-Free in Dawn via Crafted HTML Page
CVSS 8.8
CVE-2026-30007 MEDIUM
XnSoft NConvert 7.230 - Use After Free
CVSS 6.2
CVE-2026-33150 HIGH
Use After Free in libfuse
CVSS 7.8
CVE-2026-23273 HIGH
macvlan: observe an RCU grace period in macvlan_common_newlink() error path
CVSS 7.8
CVE-2026-32942 HIGH
PJSIP has ICE session use-after-free race conditions
CVSS 8.1
CVE-2026-4458 HIGH
Google Chrome < 146.0.7680.153 - Use-After-Free in Extensions
CVSS 8.8
CVE-2026-4456 HIGH
Google Chrome < 146.0.7680.153 - Use-After-Free in Digital Credentials API
CVSS 8.8
CVE-2026-4454 HIGH
Google Chrome < 146.0.7680.153 - Use-After-Free in Network
CVSS 8.8
CVE-2026-4449 HIGH
Google Chrome < 146.0.7680.153 - Use-After-Free in Blink
CVSS 8.8
CVE-2026-4446 HIGH
Google Chrome < 146.0.7680.153 - Use-After-Free in WebRTC
CVSS 8.8
CVE-2026-4445 HIGH
Google Chrome < 146.0.7680.153 - Use-After-Free in WebRTC
CVSS 8.8
CVE-2026-4441 HIGH
Google Chrome < 146.0.7680.153 - Use-After-Free in Base via Crafted HTML Page
CVSS 8.8
CVE-2026-31972 CRITICAL
samtools mpileup has use-after-free leading to an invalid read
CVSS 9.8
CVE-2026-23270 HIGH
net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks
CVSS 7.8
CVE-2026-23248 HIGH
perf/core: Fix refcount bug and potential UAF in perf_mmap
CVSS 7.8
CVE-2026-4148 HIGH
ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators
CVSS 8.8
CVE-2026-4271 MEDIUM
Libsoup: libsoup: denial of service via use-after-free in http/2 server
CVSS 5.3
CVE-2026-32724 MEDIUM
PX4 autopilot <1.17.0-rc1 - Use After Free
CVSS 5.3
CVE-2026-3979 MEDIUM
quickjs-ng quickjs <=0.12.1 - Use After Free
CVSS 5.3
CVE-2026-3936 HIGH
Google Chrome Android <146.0.7680.71 - Use After Free
CVSS 8.8
Details
Vulnerabilities 7,483
Exploit Likelihood High