The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
7,489 vulnerabilities with CWE-416
CVE-2025-26687
HIGH
Microsoft Office < 16.0.14326.22331 - Use After Free
CVSS 7.5
CVE-2025-26681
MEDIUM
Windows Win32K - GRFX Use-After-Free Privilege Escalation
CVSS 6.7
CVE-2025-26679
HIGH
Windows 10 1507-24H2 and Windows Server 2008 - Use-After-Free in RPC Endpoint Mapper Service
CVSS 7.8
CVE-2025-26671
HIGH
Windows Server 2008-2025 Use-After-Free in Remote Desktop Services
CVSS 8.1
CVE-2025-26670
HIGH
Windows LDAP - Unauthenticated Remote Code Execution via Use-After-Free
CVSS 8.1
CVE-2025-26663
HIGH
Windows LDAP - Unauthenticated Remote Code Execution via Use-After-Free
CVSS 8.1
CVE-2025-26649
HIGH
Windows 11/Server 2022/2025 Privilege Escalation via Secure Channel Race Condition
CVSS 7.0
CVE-2025-26648
HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2025-26640
HIGH
Windows 10/11, Server 2019/2022/2025 Use-After-Free in Digital Media
CVSS 7.0
CVE-2025-31498
HIGH
c-ares 1.32.3-1.34.4 - Use-After-Free in read_answers()
CVE-2025-21437
HIGH
Qualcomm Multiple Firmware - Use-After-Free in Memory Map/Unmap IOCTL Operations
CVSS 7.8
CVE-2025-21436
HIGH
Qualcomm FastConnect 7800 Firmware - Use-After-Free via Simultaneous IOCTL Calls
CVSS 7.8
CVE-2025-29815
HIGH
Microsoft Edge Chromium < 134.0.3124.66 - Use-After-Free
CVSS 7.6
CVE-2025-31115
HIGH
XZ Utils <5.8.0 - Use After Free
CVE-2025-22004
HIGH
Linux Kernel Use-After-Free in lec_send()
CVSS 7.8
CVE-2025-21999
HIGH
Linux Kernel - Use-After-Free in proc_get_inode
CVSS 7.8
CVE-2025-3066
HIGH
Google Chrome < 135.0.7049.84 - Use-After-Free in Site Isolation
CVSS 8.8
CVE-2025-21979
HIGH
Linux Kernel - Use-After-Free in WiFi cfg80211 wiphy_work
CVSS 7.8
CVE-2025-21969
HIGH
Linux Kernel < 6.6.84, 6.7.0-6.12.20, 6.13.0-6.13.8 - Use-After-Free in L2CAP Command Handling
CVSS 7.8
CVE-2025-21968
HIGH
Linux Kernel 5.5-5.9, 5.11-5.14, 5.16-6.0, 6.2-6.5, 6.7-6.11, 6.13 - Use-After-Free in HDCP Workqueue
CVSS 7.8
CVE-2025-21967
HIGH
Linux Kernel 5.15-6.6.83, 6.7-6.12.19, 6.13-6.13.7 - Use-After-Free in ksmbd_free_work_struct
CVSS 7.8
CVE-2025-21945
HIGH
Linux Kernel 5.15-6.1.130, 6.2.0-6.6.82, 6.7.0-6.12.18, 6.13.0-6.13.6 - Use-After-Free in SMB2 Lock Handling
CVSS 7.8
CVE-2025-21934
HIGH
Linux Kernel <5.4.291/<5.10.235/<5.15.179/<6.1.131/<6.6.83/<6.12.19/<6.13.7 - Use-After-Free in RapidIO
CVSS 7.8
CVE-2025-21929
HIGH
Linux Kernel - Use-After-Free in HID intel-ish-hid Driver during rmmod
CVSS 7.8
CVE-2025-21928
HIGH
Linux Kernel - Use-After-Free in HID intel-ish-hid ishtp_hid_remove
CVSS 7.8
Details
Vulnerabilities
7,489
Exploit Likelihood
High