CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,537 vulnerabilities with CWE-416
CVE-2025-0445 MEDIUM
Google Chrome <133.0.6943.53 - Use After Free
CVSS 5.4
CVE-2025-0444 MEDIUM
Google Chrome <133.0.6943.53 - Use After Free
CVSS 6.3
CVE-2025-1012 HIGH
Firefox < 115.20.0, 115.20-115.*, 128.7-128.*, >=135 - Use-After-Free via Concurrent Delazification
CVSS 7.5
CVE-2025-1010 HIGH
Firefox < 115.20.0, < 135.0 and Thunderbird >=128.0.1 <128.7.0, >=131.0 <135.0 - Use-After-Free via Custom Highlight API
CVSS 8.8
CVE-2025-1009 CRITICAL
Firefox < 115.20.0 and < 135.0 - Use-After-Free via Crafted XSLT Data
CVSS 9.8
CVE-2025-24898 MEDIUM
Rust-OpenSSL <0.10.70 - Use After Free
CVE-2025-0015 HIGH
Arm Ltd Valhall GPU Kernel Driver <r52p0 - Use After Free
CVSS 7.8
CVE-2025-21671 HIGH
Linux Kernel 6.1.122-6.1.126, 6.6.68-6.6.73, 6.12.7-6.12.10 - Use-After-Free in zram Table Handling
CVSS 7.8
CVE-2025-0762 HIGH
Google Chrome <132.0.6834.159 - Use After Free
CVSS 8.8
CVE-2025-24085 CRITICAL KEV
iPadOS < 17.7.6 - Use-After-Free
CVSS 10.0
CVE-2025-21655 MEDIUM
Linux Kernel 6.1-6.1.124, 6.2-6.6.71, 6.7-6.12.9 - Use-After-Free in io_uring EventFD Signal Handling
CVSS 4.7
CVE-2025-21652 HIGH
Linux Kernel 6.2-6.6.71, 6.7-6.12.9 - Use-After-Free in ipvlan_get_iflink
CVSS 7.8
CVE-2025-21631 HIGH
Linux Kernel - Use-After-Free in BFQ I/O Scheduler
CVSS 7.8
CVE-2025-21372 HIGH
Windows 11 24H2 and Windows Server 2022 23H2 and 2025 - Elevation of Privilege via Brokering File System Use-After-Free
CVSS 7.8
CVE-2025-21366 HIGH
Microsoft Access - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2025-21362 HIGH
Microsoft Excel - Remote Code Execution via Use-After-Free
CVSS 8.4
CVE-2025-21345 HIGH
Microsoft Office Visio - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2025-21335 HIGH KEV
Windows Hyper-V NT Kernel Integration VSP - Use-After-Free Elevation of Privilege
CVSS 7.8
CVE-2025-21334 HIGH KEV
Windows Hyper-V NT Kernel Integration VSP - Use-After-Free Elevation of Privilege
CVSS 7.8
CVE-2025-21315 HIGH
Windows 11 24H2 and Windows Server 2022 23H2 and 2025 - Elevation of Privilege via Brokering File System Use-After-Free
CVSS 7.8
CVE-2025-21307 CRITICAL
Windows 10 1507-24H2 & Server 2008-2012 RCE via Reliable Multicast Transport Driver UAF
CVSS 9.8
CVE-2025-21304 HIGH
Windows 10 1607-22H2 and Windows Server 2016-2019 - Use-After-Free in DWM Core Library
CVSS 7.8
CVE-2025-21298 CRITICAL
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008-2012 - Remote Code Execution via OLE Use-After-Free
CVSS 9.8
CVE-2025-21297 HIGH
Windows Server RCE via Use-After-Free (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.1
CVE-2025-21296 HIGH
Windows 10 1507-24H2 and Windows Server 2008-2012 - Remote Code Execution via BranchCache Use-After-Free
CVSS 7.5
Details
Vulnerabilities 7,537
Exploit Likelihood High