CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,489 vulnerabilities with CWE-416
CVE-2025-38350 HIGH
Linux Kernel - Use-After-Free in Classful Qdisc Backlog Accounting
CVSS 7.8
CVE-2025-38349 HIGH
Linux Kernel 6.4-6.6.98, 6.7-6.12.38, 6.13-6.15.6 - Use-After-Free in Event Poll Mutex Handling
CVSS 7.8
CVE-2025-7657 HIGH
Google Chrome <138.0.7204.157 - Use After Free
CVSS 8.8
CVE-2025-7042 HIGH
SOLIDWORKS Desktop 2025 - Use After Free
CVSS 7.8
CVE-2025-6973 HIGH
SOLIDWORKS Desktop 2025 - Use After Free
CVSS 7.8
CVE-2025-6972 HIGH
SOLIDWORKS Desktop 2025 - Use After Free
CVSS 7.8
CVE-2025-6971 HIGH
SOLIDWORKS Desktop 2025 - Use After Free
CVSS 7.8
CVE-2025-3631 MEDIUM
IBM MQ Appliance 9.3.2-9.3.5.1 and 9.4.0.0-9.4.0.11 - Use-After-Free in AMQRMPPA Channel Process
CVSS 6.5
CVE-2025-52946 HIGH
Juniper Junos OS and Junos OS Evolved - Denial of Service via Malformed BGP AS PATH Attribute
CVSS 7.5
CVE-2025-7425 HIGH
libxml2 < 2.15.2 - Use-After-Free in XSLT Key Function Tree Fragment Handling
CVSS 7.8
CVE-2025-38346 HIGH
Linux Kernel 4.15-6.15.4 - Use-After-Free in ftrace_mod_get_kallsym
CVSS 7.8
CVE-2025-38323 HIGH
Linux Kernel - Use-After-Free in ATM LEC Component
CVSS 7.8
CVE-2025-38289 HIGH
Linux Kernel - Use-After-Free in SCSI LPFC dev_loss_tmo_callbk
CVSS 7.8
CVE-2025-38259 HIGH
Linux Kernel 5.1-6.15.4 - Use-After-Free in ASoC WCD9335 Regulator Supply Handling
CVSS 7.8
CVE-2025-38250 HIGH
Linux Kernel 3.4-6.6.96, 6.7-6.12.35, 6.13-6.15.4 - Use-After-Free in vhci_flush
CVSS 7.8
CVE-2025-38248 HIGH
Linux Kernel 5.15-6.15.5 - Use-After-Free in Bridge Multicast Router Port Configuration
CVSS 7.8
CVE-2025-49735 HIGH
Windows Server 2012-2025 Unauthenticated RCE via KDC Proxy Service Use-After-Free
CVSS 8.1
CVE-2025-49733 HIGH
Windows Win32K - Use-After-Free in ICOMP
CVSS 7.8
CVE-2025-49726 HIGH
Windows 10/11, Server 2016/2019/2022 Use-After-Free in Notification Service
CVSS 7.8
CVE-2025-49725 HIGH
Windows 10 1607-22H2, Windows 11 22H2-24H2, Windows Server 2016-2022 - Use-After-Free in Notification Service
CVSS 7.8
CVE-2025-49724 HIGH
Windows Connected Devices Platform Service - Remote Code Execution via Use-After-Free
CVSS 8.8
CVE-2025-49711 HIGH
Microsoft Excel - Use-After-Free
CVSS 7.8
CVE-2025-49703 HIGH
Microsoft Office Word - Use-After-Free
CVSS 7.8
CVE-2025-49700 HIGH
Microsoft Office Word - Use-After-Free
CVSS 7.8
CVE-2025-49699 HIGH
Microsoft 365 Apps and Office - Use-After-Free
CVSS 7.0
Details
Vulnerabilities 7,489
Exploit Likelihood High