CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,537 vulnerabilities with CWE-416
CVE-2024-50264 HIGH
Linux Kernel < 4.19.324 - Use After Free
CVSS 7.8
CVE-2024-52568 HIGH
Tecnomatix Plant Simulation < 2302.0018 - Use-After-Free in WRL File Parser
CVSS 7.8
CVE-2024-40885 MEDIUM
Intel(R) Server M20NTP BIOS - Privilege Escalation
CVSS 6.4
CVE-2024-34747 HIGH
Android - Use-After-Free in DevmemXIntMapPages
CVSS 7.8
CVE-2024-4741 HIGH
OpenSSL 3.3.0-3.3.1, 3.2.0-3.2.2, 3.1.0-3.1.6, 3.0.0-3.0.14, 1.1.1-1.1.1y - Use-After-Free in SSL_free_buffers
CVSS 7.5
CVE-2024-11113 HIGH
Google Chrome < 131.0.6778.69 - Use-After-Free in Accessibility
CVSS 8.8
CVE-2024-11112 HIGH
Google Chrome < 131.0.6778.69 - Use-After-Free in Media via Crafted HTML Page
CVSS 8.8
CVE-2024-49032 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Graphics Use-After-Free
CVSS 7.8
CVE-2024-49027 HIGH
Microsoft Excel - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2024-49021 HIGH
Microsoft SQL Server 2016-2022 Remote Code Execution
CVSS 7.8
CVE-2024-49016 HIGH
SQL Server 2016, 2017, 2019 - Remote Code Execution via Use-After-Free in Native Client
CVSS 8.8
CVE-2024-49003 HIGH
SQL Server 2016-2019 Remote Code Execution via Use-After-Free in Native Client
CVSS 8.8
CVE-2024-43642 HIGH
Windows 11 22H2/23H2/24H2 and Windows Server 2022/2022 23H2/2025 - Denial of Service via SMB Use-After-Free
CVSS 7.5
CVE-2024-43625 HIGH
Windows 11 22H2/23H2/24H2 and Windows Server 2022/2022 23H2/2025 - Use-After-Free in VMSwitch
CVSS 8.1
CVE-2024-43459 HIGH
SQL Server 2016-2019 Remote Code Execution via Use-After-Free
CVSS 8.8
CVE-2024-49526 HIGH
Adobe Animate < 23.0.8 - Use-After-Free
CVSS 7.8
CVE-2024-9420 HIGH
Ivanti Connect Secure < 22.7R2.3 and < 9.1R18.9 - Authenticated Remote Code Execution via Use-After-Free
CVSS 8.8
CVE-2024-50261 HIGH
Linux Kernel 6.1-6.1.115, 6.2-6.6.59, 6.7-6.11.6 - Use-After-Free in macsec_free_netdev
CVSS 7.8
CVE-2024-50257 HIGH
Linux Kernel 5.15-5.15.170, 5.16-6.1.115, 6.2-6.6.59, 6.7-6.11.6 - Use-After-Free in get_info()
CVSS 7.8
CVE-2024-50226 HIGH
Linux Kernel 6.0-6.6.60, 6.7-6.11.7 - Use-After-Free in CXL Port Decoder Shutdown
CVSS 7.8
CVE-2024-50217 HIGH
Linux Kernel 4.8-6.11.7 - Use-After-Free in Btrfs Device Handling
CVSS 7.8
CVE-2024-27530 HIGH
wasm3 139076a - Use-After-Free in ForEachModule
CVSS 8.4
CVE-2024-50186 HIGH
Linux Kernel 5.15.162-5.15.168 - Use-After-Free in Socket Creation Error Path
CVSS 7.8
CVE-2024-50154 HIGH
Linux Kernel 4.1.11-4.1.11 - Use-After-Free in reqsk_timer_handler
CVSS 7.0
CVE-2024-50150 HIGH
Linux Kernel - Use-After-Free in USB Type-C Altmode Device Release
CVSS 7.8
Details
Vulnerabilities 7,537
Exploit Likelihood High