CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,484 vulnerabilities with CWE-416
CVE-2026-25954 HIGH
FreeRDP < 3.23.0 - Use-After-Free in xf_rail_server_local_move_size
CVSS 7.5
CVE-2026-25953 CRITICAL
FreeRDP < 3.23.0 - Use-After-Free in xf_rail Window Handling
CVSS 9.8
CVE-2026-25952 CRITICAL
FreeRDP < 3.23.0 - Use-After-Free in xf_SetWindowMinMaxInfo
CVSS 9.8
CVE-2026-2804 MEDIUM
Firefox < 148.0 - Use-After-Free in JavaScript WebAssembly Component
CVSS 5.4
CVE-2026-2799 CRITICAL
Firefox < 148.0 - Use-After-Free in DOM Core & HTML Component
CVSS 9.8
CVE-2026-2798 HIGH
Firefox < 148.0 - Use-After-Free in DOM Core & HTML Component
CVSS 8.8
CVE-2026-2797 CRITICAL
Firefox < 148.0 - Use-After-Free in JavaScript GC
CVSS 9.8
CVE-2026-2795 CRITICAL
Firefox < 148.0 - Use-After-Free in JavaScript GC
CVSS 9.8
CVE-2026-2789 CRITICAL
Firefox < 115.33.0, 140.8-140.*, >=148 - Use-After-Free in Graphics: ImageLib
CVSS 9.8
CVE-2026-2787 CRITICAL
Firefox < 115.33.0, 140.8.0-140.*, <148.0 and Thunderbird <140.8.0, <148.0 - Use-After-Free in DOM Window and Location
CVSS 9.8
CVE-2026-2786 CRITICAL
Firefox < 148.0 and 140.8-140.* - Use-After-Free in JavaScript Engine
CVSS 9.8
CVE-2026-2772 CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Use-After-Free in Audio/Video Playback
CVSS 9.8
CVE-2026-2770 CRITICAL
Firefox <115.33.0, 115.33-115.*, <148.0, >=148; Thunderbird <140.8.0, 140.8-140.*, >=148 Use-After-Free
CVSS 9.8
CVE-2026-2769 HIGH
Firefox < 115.33.0, 140.8-140.*, >=148 - Use-After-Free in IndexedDB
CVSS 8.8
CVE-2026-2767 CRITICAL
Firefox < 148.0 and Firefox ESR < 140.8.0 - Use-After-Free in JavaScript WebAssembly Component
CVSS 9.8
CVE-2026-2766 CRITICAL
Firefox < 148 and Firefox ESR < 140.8 - Use-After-Free in JavaScript Engine JIT
CVSS 9.8
CVE-2026-2765 CRITICAL
Firefox < 148.0 and < 140.8.0 - Use-After-Free in JavaScript Engine
CVSS 9.8
CVE-2026-2764 CRITICAL
Firefox <148 - Use After Free
CVSS 9.8
CVE-2026-2763 CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Use-After-Free in JavaScript Engine
CVSS 9.8
CVE-2026-2758 CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Use-After-Free in JavaScript GC
CVSS 9.8
CVE-2026-26983 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Use After Free
CVSS 5.3
CVE-2026-25983 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Use After Free
CVSS 5.3
CVE-2026-2889 LOW
CCExtractor <=0.96.5 - Use After Free
CVSS 3.3
CVE-2026-2408 MEDIUM
Tanium Cloud Workloads Enforce - Use After Free
CVSS 4.7
CVE-2026-26203 MEDIUM
pjsip < 2.17 - Use-After-Free in H.264 Packetizer
CVSS 6.5
Details
Vulnerabilities 7,484
Exploit Likelihood High