CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,537 vulnerabilities with CWE-416
CVE-2025-21715 HIGH
Linux Kernel 4.4.262-4.5 - Use-After-Free in dm9000_drv_remove
CVSS 7.8
CVE-2025-21714 HIGH
Linux Kernel 5.5-6.12.12, 6.13.0-6.13.1, 6.14 - Use-After-Free in RDMA/mlx5 Implicit ODP MR Destroy
CVSS 7.8
CVE-2025-26601 HIGH
Tigervnc < 21.1.16 - Use After Free
CVSS 7.8
CVE-2025-26600 HIGH
Tigervnc < 21.1.16 - Use After Free
CVSS 7.8
CVE-2025-26594 HIGH
Tigervnc < 21.1.16 - Use After Free
CVSS 7.8
CVE-2025-1006 HIGH
Google Chrome <133.0.6943.126 - Use After Free
CVSS 8.8
CVE-2025-26623 CRITICAL
exiv2 0.28.0-0.28.4 - Use-After-Free via Crafted Image Metadata Write
CVSS 9.8
CVE-2025-0622 MEDIUM
Red Hat Enterprise Linux 10 - Use-After-Free in GRUB2 Module Hook Handling
CVSS 6.4
CVE-2025-26603 MEDIUM
Vim < 9.1.1115 - Use-After-Free via :display Command Redirection
CVSS 4.2
CVE-2025-21703 HIGH
Linux Kernel - Use-After-Free in DRR Active List via qdisc_tree_reduce_backlog
CVSS 7.8
CVE-2025-0997 HIGH
Google Chrome < 133.0.6943.98 - Use-After-Free in Navigation via Crafted Chrome Extension
CVSS 8.1
CVE-2025-0995 HIGH
Google Chrome < 133.0.6943.98 - Use-After-Free in V8 via Crafted HTML Page
CVSS 8.8
CVE-2025-21700 HIGH
Linux kernel - Privilege Escalation
CVSS 7.8
CVE-2025-0899 HIGH
PDF-XChange Editor < 10.4.1.389 - Use-After-Free in AcroForm Handling
CVSS 8.8
CVE-2025-21406 HIGH
Windows Telephony Service - Remote Code Execution via Use-After-Free
CVSS 8.8
CVE-2025-21397 HIGH
Microsoft 365 Apps - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2025-21394 HIGH
Microsoft Excel - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2025-21392 HIGH
Microsoft 365 Apps and Office - Remote Code Execution
CVSS 7.8
CVE-2025-21387 HIGH
Microsoft Excel - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2025-21386 HIGH
Microsoft Excel - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2025-21379 HIGH
Windows 11 24H2 and Windows Server 2025 < 10.0.26100.3194 - Remote Code Execution via DHCP Client Service Use-After-Free
CVSS 7.1
CVE-2025-21367 HIGH
Windows 10/11, Server 2019/2022/2025 - Elevation of Privilege via Win32 Kernel Use-After-Free
CVSS 7.8
CVE-2025-21159 HIGH
Adobe Illustrator < 28.7.4 - Use-After-Free
CVSS 7.8
CVE-2025-21693 HIGH
Linux Kernel 5.11-6.12.11 - Use-After-Free in zswap CPU Hotunplug
CVSS 7.8
CVE-2025-0304 HIGH
OpenHarmony <4.1.2 - Use After Free
CVSS 8.8
Details
Vulnerabilities 7,537
Exploit Likelihood High