The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
7,486 vulnerabilities with CWE-416
CVE-2025-11460
HIGH
Google Chrome <141.0.7390.65 - Use After Free
CVSS 8.8
CVE-2025-11219
LOW
Google Chrome <141.0.7390.54 - Use After Free
CVSS 3.1
CVE-2025-54335
MEDIUM
Samsung Exynos 1480 1580 2400 2500 Firmware - Use-After-Free in Xclipse GPU Driver
CVSS 6.5
CVE-2025-52910
CRITICAL
Samsung Exynos 1280, 1330, 1380, 1480, 2200, 2400 Firmware - Use-After-Free in GPU
CVSS 9.8
CVE-2025-20745
MEDIUM
Android - Use-After-Free in apusys
CVSS 4.2
CVE-2025-20744
MEDIUM
Android - Use-After-Free in PDA
CVSS 4.2
CVE-2025-20743
MEDIUM
Android - Use-After-Free in clkdbg
CVSS 4.2
CVE-2025-43478
MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Use-After-Free
CVSS 5.5
CVE-2025-43457
MEDIUM
Safari < 26.1 - Use-After-Free via Malicious Web Content
CVSS 6.5
CVE-2025-43438
MEDIUM
Safari < 26.1 - Use-After-Free
CVSS 4.3
CVE-2025-43434
MEDIUM
Safari < 26.1 - Use-After-Free via Malicious Web Content
CVSS 4.3
CVE-2025-43432
MEDIUM
Safari < 26.1 - Use-After-Free via Maliciously Crafted Web Content
CVSS 4.3
CVE-2025-29699
MEDIUM
NetSurf 3.11 - Use-After-Free in dom_node_set_text_content
CVSS 6.5
CVE-2025-57108
CRITICAL
VTK < 9.5.0 - Use-After-Free in vtkGLTFDocumentLoader
CVSS 9.8
CVE-2025-57109
MEDIUM
Kitware VTK 9.5.0 - Heap Use-After-Free in vtkGLTFImporter::ImportActors
CVSS 6.5
CVE-2025-62230
HIGH
Xwayland < 24.1.9 - Use-After-Free in Xkb Extension Client Resource Cleanup
CVSS 7.3
CVE-2025-62229
HIGH
X.Org X server and Xwayland - Use After Free
CVSS 7.3
CVE-2025-11465
HIGH
Ashlar-Vellum Cobalt - Use After Free RCE
CVSS 7.8
CVE-2025-62788
HIGH
Wazuh < 4.11.0 - Use-After-Free in w_copy_event_for_log()
CVSS 7.5
CVE-2025-53814
HIGH
GCC Productions Inc. Fade In <4.2.0 - Use After Free
CVSS 7.8
CVE-2025-12380
CRITICAL
Firefox 142.0-144.0.1 - Use-After-Free via WebGPU IPC Calls
CVSS 9.8
CVE-2025-12205
MEDIUM
Kamailio 5.5 - Use-After-Free in Configuration File Handler
CVSS 5.3
CVE-2025-12105
HIGH
libsoup < 3.6.5 - Use-After-Free in Asynchronous Message Queue Handling
CVSS 7.5
CVE-2025-11979
MEDIUM
MongoDB 7.0.0-7.0.24 - Authenticated Denial of Service via DDL Operation Buffer Over-Read
CVSS 5.3
CVE-2025-11677
MEDIUM
libwebsockets 3-4.4.1,4.3.6 - Use-After-Free in WebSocket Server Handshake
Details
Vulnerabilities
7,486
Exploit Likelihood
High