The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
7,486 vulnerabilities with CWE-416
CVE-2025-11797
HIGH
Autodesk 3ds Max 2026-2026.3 - Use-After-Free via Malicious DWG File
CVSS 7.8
CVE-2025-40149
HIGH
Linux Kernel 4.18-6.17.2 - Use-After-Free in TLS Socket Option Handling
CVSS 7.8
CVE-2025-64531
HIGH
Substance 3D Stager < 3.1.6 - Use-After-Free
CVSS 7.8
CVE-2025-61834
HIGH
Substance 3D Stager < 3.1.6 - Use-After-Free
CVSS 7.8
CVE-2025-61842
MEDIUM
Format Plugins <= 1.1.1 - Use-After-Free via Malicious File
CVSS 5.5
CVE-2025-62216
HIGH
Microsoft 365 Apps - Use-After-Free
CVSS 7.8
CVE-2025-62213
HIGH
Windows 10 1607-22H2, Windows 11 23H2-25H2, Windows Server 2008-2016 - Privilege Escalation via Use-After-Free in AFD
CVSS 7.0
CVE-2025-62205
HIGH
Microsoft 365 Apps and Office Long Term Servicing Channel - Use-After-Free
CVSS 7.8
CVE-2025-62203
HIGH
Microsoft Excel - Use-After-Free
CVSS 7.8
CVE-2025-62199
HIGH
Microsoft Office < 16.0.19426.20044 - Use-After-Free
CVSS 7.8
CVE-2025-60723
MEDIUM
Windows DirectX - Denial of Service via Race Condition
CVSS 6.3
CVE-2025-60717
HIGH
Windows Broadcast DVR User Service - Privilege Escalation
CVSS 7.0
CVE-2025-60716
HIGH
Windows DirectX - Privilege Escalation
CVSS 7.0
CVE-2025-60707
HIGH
Multimedia Class Scheduler Service (MMCSS) - Privilege Escalation
CVSS 7.8
CVE-2025-59515
HIGH
Windows 10/11, Server 2019/2022/2025 - Use-After-Free in Broadcast DVR User Service
CVSS 7.0
CVE-2025-61818
HIGH
Adobe InCopy < 19.5.5 - Use-After-Free
CVSS 7.8
CVE-2025-61817
HIGH
Adobe InCopy < 19.5.5 - Use-After-Free
CVSS 7.8
CVE-2025-61815
HIGH
Adobe InDesign < 19.5.5 - Use-After-Free
CVSS 7.8
CVE-2025-61814
HIGH
Adobe InDesign < 19.5.5 - Use-After-Free via Malicious File
CVSS 7.8
CVE-2025-13020
HIGH
Firefox < 145.0 and Firefox ESR < 140.5 - Use-After-Free in WebRTC Audio/Video Component
CVSS 8.8
CVE-2025-13014
HIGH
Firefox < 145.0 and ESR < 140.5 and ESR 115.30 - Use-After-Free in Audio/Video Component
CVSS 8.8
CVE-2025-64183
HIGH
OpenEXR 3.2.0-3.2.4 3.3.0-3.3.5 3.4.0-3.4.2 - Use-After-Free in PyObject_StealAttrString
CVSS 7.5
CVE-2025-12438
HIGH
Google Chrome < 142.0.7444.59 - Use-After-Free in Ozone via Crafted HTML Page
CVSS 8.8
CVE-2025-12437
HIGH
Google Chrome < 142.0.7444.59 - Use-After-Free in PageInfo
CVSS 7.5
CVE-2025-11756
HIGH
Google Chrome < 141.0.7390.107 - Use-After-Free in Safe Browsing
CVSS 8.8
Details
Vulnerabilities
7,486
Exploit Likelihood
High