CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,486 vulnerabilities with CWE-416
CVE-2025-11460 HIGH
Google Chrome <141.0.7390.65 - Use After Free
CVSS 8.8
CVE-2025-11219 LOW
Google Chrome <141.0.7390.54 - Use After Free
CVSS 3.1
CVE-2025-54335 MEDIUM
Samsung Exynos 1480 1580 2400 2500 Firmware - Use-After-Free in Xclipse GPU Driver
CVSS 6.5
CVE-2025-52910 CRITICAL
Samsung Exynos 1280, 1330, 1380, 1480, 2200, 2400 Firmware - Use-After-Free in GPU
CVSS 9.8
CVE-2025-20745 MEDIUM
Android - Use-After-Free in apusys
CVSS 4.2
CVE-2025-20744 MEDIUM
Android - Use-After-Free in PDA
CVSS 4.2
CVE-2025-20743 MEDIUM
Android - Use-After-Free in clkdbg
CVSS 4.2
CVE-2025-43478 MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Use-After-Free
CVSS 5.5
CVE-2025-43457 MEDIUM
Safari < 26.1 - Use-After-Free via Malicious Web Content
CVSS 6.5
CVE-2025-43438 MEDIUM
Safari < 26.1 - Use-After-Free
CVSS 4.3
CVE-2025-43434 MEDIUM
Safari < 26.1 - Use-After-Free via Malicious Web Content
CVSS 4.3
CVE-2025-43432 MEDIUM
Safari < 26.1 - Use-After-Free via Maliciously Crafted Web Content
CVSS 4.3
CVE-2025-29699 MEDIUM
NetSurf 3.11 - Use-After-Free in dom_node_set_text_content
CVSS 6.5
CVE-2025-57108 CRITICAL
VTK < 9.5.0 - Use-After-Free in vtkGLTFDocumentLoader
CVSS 9.8
CVE-2025-57109 MEDIUM
Kitware VTK 9.5.0 - Heap Use-After-Free in vtkGLTFImporter::ImportActors
CVSS 6.5
CVE-2025-62230 HIGH
Xwayland < 24.1.9 - Use-After-Free in Xkb Extension Client Resource Cleanup
CVSS 7.3
CVE-2025-62229 HIGH
X.Org X server and Xwayland - Use After Free
CVSS 7.3
CVE-2025-11465 HIGH
Ashlar-Vellum Cobalt - Use After Free RCE
CVSS 7.8
CVE-2025-62788 HIGH
Wazuh < 4.11.0 - Use-After-Free in w_copy_event_for_log()
CVSS 7.5
CVE-2025-53814 HIGH
GCC Productions Inc. Fade In <4.2.0 - Use After Free
CVSS 7.8
CVE-2025-12380 CRITICAL
Firefox 142.0-144.0.1 - Use-After-Free via WebGPU IPC Calls
CVSS 9.8
CVE-2025-12205 MEDIUM
Kamailio 5.5 - Use-After-Free in Configuration File Handler
CVSS 5.3
CVE-2025-12105 HIGH
libsoup < 3.6.5 - Use-After-Free in Asynchronous Message Queue Handling
CVSS 7.5
CVE-2025-11979 MEDIUM
MongoDB 7.0.0-7.0.24 - Authenticated Denial of Service via DDL Operation Buffer Over-Read
CVSS 5.3
CVE-2025-11677 MEDIUM
libwebsockets 3-4.4.1,4.3.6 - Use-After-Free in WebSocket Server Handshake
Details
Vulnerabilities 7,486
Exploit Likelihood High