CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,489 vulnerabilities with CWE-416
CVE-2025-49698 HIGH
Microsoft Office Word - Use-After-Free
CVSS 7.8
CVE-2025-49695 HIGH
Microsoft 365 Apps and Office - Use-After-Free
CVSS 8.4
CVE-2025-49685 HIGH
Windows 10/11, Server 2019/2022 Use-After-Free in Search Component
CVSS 7.0
CVE-2025-49682 HIGH
Windows 10/11, Server 2022/2025 - Authenticated Use-After-Free in Media
CVSS 7.3
CVE-2025-49677 HIGH
Windows 11 22H2 < 10.0.22621.5624 - Authenticated Use-After-Free in Brokering File System
CVSS 7.0
CVE-2025-49675 HIGH
Windows 10/11, Server 2008 - Use-After-Free in Kernel Streaming WOW Thunk
CVSS 7.8
CVE-2025-49665 HIGH
Windows 10/11, Server 2012/2016 Privilege Escalation via Workspace Broker Race Condition
CVSS 7.8
CVE-2025-49660 HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2012-2016 - Authenticated Use-After-Free in Event Tracing
CVSS 7.8
CVE-2025-48821 HIGH
Windows UPnP Device Host - Privilege Escalation
CVSS 7.1
CVE-2025-48806 HIGH
Microsoft MPEG-2 Video Extension - Use After Free
CVSS 7.8
CVE-2025-48000 HIGH
Windows 10/11, Server 2016-2022 - Use-After-Free in Connected Devices Platform Service
CVSS 7.8
CVE-2025-47991 HIGH
Windows 10/11, Server 2016-2022 - Authenticated Use-After-Free in Input Method Editor
CVSS 7.8
CVE-2025-47986 HIGH
Windows 10/11, Server 2008 - Privilege Escalation via Universal Print Management Service UAF
CVSS 8.8
CVE-2025-47976 HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008 - Authenticated Use-After-Free in SSDP Service
CVSS 7.8
CVE-2025-27056 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2025-27050 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2025-27047 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2025-21466 HIGH
Qualcomm AQT1000 and FastConnect Firmware - Use-After-Free in Event Trigger Command Processing
CVSS 7.8
CVE-2025-38236 HIGH
Linux Kernel 5.15-6.15.4 - Use-After-Free in AF_UNIX OOB Skb Handling
CVSS 7.8
CVE-2025-53185 MEDIUM
Huawei EMUI and HarmonyOS - Use-After-Free in Memory Management Module
CVSS 6.6
CVE-2025-38227 HIGH
Linux Kernel - Use-After-Free in vidtv_mux_init
CVSS 7.8
CVE-2025-38212 HIGH
Linux Kernel - Use-After-Free in IPCS Lookup via RCU Protection Bypass
CVSS 7.8
CVE-2025-38211 HIGH
Linux Kernel - Use-After-Free in RDMA/iwcm Work Objects
CVSS 7.8
CVE-2025-38209 HIGH
Linux Kernel 6.15-6.15.3 - Use-After-Free in NVMe-TCP Admin Queue Configuration
CVSS 7.8
CVE-2025-38187 HIGH
Linux Kernel 6.7-6.15.4 - Use-After-Free in r535_gsp_rpc_push
CVSS 7.8
Details
Vulnerabilities 7,489
Exploit Likelihood High