The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
7,484 vulnerabilities with CWE-416
CVE-2026-25170
HIGH
Windows Hyper-V - Privilege Escalation
CVSS 7.0
CVE-2026-25167
HIGH
Microsoft Brokering File System - Privilege Escalation
CVSS 7.4
CVE-2026-24295
HIGH
Windows Device Association Service - Privilege Escalation
CVSS 7.0
CVE-2026-24292
HIGH
Connected Devices Platform Service - Privilege Escalation
CVSS 7.8
CVE-2026-24289
HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2026-24285
HIGH
Windows Win32K - Privilege Escalation
CVSS 7.0
CVE-2026-23671
HIGH
Windows Bluetooth RFCOM Driver - Privilege Escalation
CVSS 7.0
CVE-2026-23669
HIGH
Windows Print Spooler - Use After Free
CVSS 8.8
CVE-2026-23667
HIGH
Broadcast DVR - Privilege Escalation
CVSS 7.0
CVE-2026-28688
MEDIUM
ImageMagick <7.1.2-16/6.9.13-41 - Use After Free
CVSS 4.0
CVE-2026-28687
MEDIUM
ImageMagick <7.1.2-16/6.9.13-41 - Use After Free
CVSS 5.3
CVE-2026-28799
HIGH
pjsip < 2.17 - Use-After-Free in Event Subscription Framework
CVSS 7.5
CVE-2026-22040
MEDIUM
NanoMQ < 0.24.6 - Use-After-Free via High-Frequency Publish and Reconnect Traffic
CVSS 5.3
CVE-2026-23234
HIGH
Linux Kernel - Use-After-Free in f2fs_write_end_io
CVSS 7.8
CVE-2026-23231
HIGH
Linux Kernel Use-After-Free in nf_tables_addchain
CVSS 7.8
CVE-2026-0027
MEDIUM
Android - Use-After-Free in smmu_detach_dev
CVSS 6.7
CVE-2026-20443
MEDIUM
Display - Privilege Escalation
CVSS 6.7
CVE-2026-20442
MEDIUM
Android - Local Denial of Service via Use-After-Free in Display Component
CVSS 4.4
CVE-2026-20439
MEDIUM
Android MediaTek imgsys - Use-After-Free Denial of Service
CVSS 4.4
CVE-2026-20437
MEDIUM
MAE - Use After Free
CVSS 4.4
CVE-2026-27950
HIGH
FreeRDP < 3.23.0 - Use-After-Free in SDL2 Pointer Implementation
CVSS 7.5
CVE-2026-26986
HIGH
FreeRDP < 3.23.0 - Use-After-Free in xf_rail_window_common
CVSS 7.5
CVE-2026-25997
CRITICAL
FreeRDP < 3.23.0 - Use-After-Free in Clipboard Format Handling
CVSS 9.8
CVE-2026-25959
CRITICAL
FreeRDP < 3.23.0 - Use-After-Free in Clipboard Data Handling
CVSS 9.8
CVE-2026-25955
CRITICAL
FreeRDP < 3.23.0 - Use-After-Free in xf_AppUpdateWindowFromSurface
CVSS 9.8
Details
Vulnerabilities
7,484
Exploit Likelihood
High