CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,489 vulnerabilities with CWE-416
CVE-2025-26687 HIGH
Microsoft Office < 16.0.14326.22331 - Use After Free
CVSS 7.5
CVE-2025-26681 MEDIUM
Windows Win32K - GRFX Use-After-Free Privilege Escalation
CVSS 6.7
CVE-2025-26679 HIGH
Windows 10 1507-24H2 and Windows Server 2008 - Use-After-Free in RPC Endpoint Mapper Service
CVSS 7.8
CVE-2025-26671 HIGH
Windows Server 2008-2025 Use-After-Free in Remote Desktop Services
CVSS 8.1
CVE-2025-26670 HIGH
Windows LDAP - Unauthenticated Remote Code Execution via Use-After-Free
CVSS 8.1
CVE-2025-26663 HIGH
Windows LDAP - Unauthenticated Remote Code Execution via Use-After-Free
CVSS 8.1
CVE-2025-26649 HIGH
Windows 11/Server 2022/2025 Privilege Escalation via Secure Channel Race Condition
CVSS 7.0
CVE-2025-26648 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2025-26640 HIGH
Windows 10/11, Server 2019/2022/2025 Use-After-Free in Digital Media
CVSS 7.0
CVE-2025-31498 HIGH
c-ares 1.32.3-1.34.4 - Use-After-Free in read_answers()
CVE-2025-21437 HIGH
Qualcomm Multiple Firmware - Use-After-Free in Memory Map/Unmap IOCTL Operations
CVSS 7.8
CVE-2025-21436 HIGH
Qualcomm FastConnect 7800 Firmware - Use-After-Free via Simultaneous IOCTL Calls
CVSS 7.8
CVE-2025-29815 HIGH
Microsoft Edge Chromium < 134.0.3124.66 - Use-After-Free
CVSS 7.6
CVE-2025-31115 HIGH
XZ Utils <5.8.0 - Use After Free
CVE-2025-22004 HIGH
Linux Kernel Use-After-Free in lec_send()
CVSS 7.8
CVE-2025-21999 HIGH
Linux Kernel - Use-After-Free in proc_get_inode
CVSS 7.8
CVE-2025-3066 HIGH
Google Chrome < 135.0.7049.84 - Use-After-Free in Site Isolation
CVSS 8.8
CVE-2025-21979 HIGH
Linux Kernel - Use-After-Free in WiFi cfg80211 wiphy_work
CVSS 7.8
CVE-2025-21969 HIGH
Linux Kernel < 6.6.84, 6.7.0-6.12.20, 6.13.0-6.13.8 - Use-After-Free in L2CAP Command Handling
CVSS 7.8
CVE-2025-21968 HIGH
Linux Kernel 5.5-5.9, 5.11-5.14, 5.16-6.0, 6.2-6.5, 6.7-6.11, 6.13 - Use-After-Free in HDCP Workqueue
CVSS 7.8
CVE-2025-21967 HIGH
Linux Kernel 5.15-6.6.83, 6.7-6.12.19, 6.13-6.13.7 - Use-After-Free in ksmbd_free_work_struct
CVSS 7.8
CVE-2025-21945 HIGH
Linux Kernel 5.15-6.1.130, 6.2.0-6.6.82, 6.7.0-6.12.18, 6.13.0-6.13.6 - Use-After-Free in SMB2 Lock Handling
CVSS 7.8
CVE-2025-21934 HIGH
Linux Kernel <5.4.291/<5.10.235/<5.15.179/<6.1.131/<6.6.83/<6.12.19/<6.13.7 - Use-After-Free in RapidIO
CVSS 7.8
CVE-2025-21929 HIGH
Linux Kernel - Use-After-Free in HID intel-ish-hid Driver during rmmod
CVSS 7.8
CVE-2025-21928 HIGH
Linux Kernel - Use-After-Free in HID intel-ish-hid ishtp_hid_remove
CVSS 7.8
Details
Vulnerabilities 7,489
Exploit Likelihood High