CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,486 vulnerabilities with CWE-416
CVE-2025-11797 HIGH
Autodesk 3ds Max 2026-2026.3 - Use-After-Free via Malicious DWG File
CVSS 7.8
CVE-2025-40149 HIGH
Linux Kernel 4.18-6.17.2 - Use-After-Free in TLS Socket Option Handling
CVSS 7.8
CVE-2025-64531 HIGH
Substance 3D Stager < 3.1.6 - Use-After-Free
CVSS 7.8
CVE-2025-61834 HIGH
Substance 3D Stager < 3.1.6 - Use-After-Free
CVSS 7.8
CVE-2025-61842 MEDIUM
Format Plugins <= 1.1.1 - Use-After-Free via Malicious File
CVSS 5.5
CVE-2025-62216 HIGH
Microsoft 365 Apps - Use-After-Free
CVSS 7.8
CVE-2025-62213 HIGH
Windows 10 1607-22H2, Windows 11 23H2-25H2, Windows Server 2008-2016 - Privilege Escalation via Use-After-Free in AFD
CVSS 7.0
CVE-2025-62205 HIGH
Microsoft 365 Apps and Office Long Term Servicing Channel - Use-After-Free
CVSS 7.8
CVE-2025-62203 HIGH
Microsoft Excel - Use-After-Free
CVSS 7.8
CVE-2025-62199 HIGH
Microsoft Office < 16.0.19426.20044 - Use-After-Free
CVSS 7.8
CVE-2025-60723 MEDIUM
Windows DirectX - Denial of Service via Race Condition
CVSS 6.3
CVE-2025-60717 HIGH
Windows Broadcast DVR User Service - Privilege Escalation
CVSS 7.0
CVE-2025-60716 HIGH
Windows DirectX - Privilege Escalation
CVSS 7.0
CVE-2025-60707 HIGH
Multimedia Class Scheduler Service (MMCSS) - Privilege Escalation
CVSS 7.8
CVE-2025-59515 HIGH
Windows 10/11, Server 2019/2022/2025 - Use-After-Free in Broadcast DVR User Service
CVSS 7.0
CVE-2025-61818 HIGH
Adobe InCopy < 19.5.5 - Use-After-Free
CVSS 7.8
CVE-2025-61817 HIGH
Adobe InCopy < 19.5.5 - Use-After-Free
CVSS 7.8
CVE-2025-61815 HIGH
Adobe InDesign < 19.5.5 - Use-After-Free
CVSS 7.8
CVE-2025-61814 HIGH
Adobe InDesign < 19.5.5 - Use-After-Free via Malicious File
CVSS 7.8
CVE-2025-13020 HIGH
Firefox < 145.0 and Firefox ESR < 140.5 - Use-After-Free in WebRTC Audio/Video Component
CVSS 8.8
CVE-2025-13014 HIGH
Firefox < 145.0 and ESR < 140.5 and ESR 115.30 - Use-After-Free in Audio/Video Component
CVSS 8.8
CVE-2025-64183 HIGH
OpenEXR 3.2.0-3.2.4 3.3.0-3.3.5 3.4.0-3.4.2 - Use-After-Free in PyObject_StealAttrString
CVSS 7.5
CVE-2025-12438 HIGH
Google Chrome < 142.0.7444.59 - Use-After-Free in Ozone via Crafted HTML Page
CVSS 8.8
CVE-2025-12437 HIGH
Google Chrome < 142.0.7444.59 - Use-After-Free in PageInfo
CVSS 7.5
CVE-2025-11756 HIGH
Google Chrome < 141.0.7390.107 - Use-After-Free in Safe Browsing
CVSS 8.8
Details
Vulnerabilities 7,486
Exploit Likelihood High