CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,537 vulnerabilities with CWE-416
CVE-2024-50149 MEDIUM
Linux Kernel 6.10-6.11.5 - Use-After-Free in drm/xe TDR Job Handling
CVSS 5.5
CVE-2024-10827 HIGH
Google Chrome < 130.0.6723.116 - Use-After-Free in Serial
CVSS 8.8
CVE-2024-10826 HIGH
Google Chrome < 130.0.6723.116 - Use-After-Free in Family Experiences via Crafted HTML Page
CVSS 8.8
CVE-2024-50130 HIGH
Linux Kernel 6.4-6.6.58, 6.7-6.11.5 - Use-After-Free in Netfilter BPF Net Namespace Handling
CVSS 7.8
CVE-2024-50127 HIGH
Linux Kernel 5.2-6.11.6 Use-After-Free in taprio_change()
CVSS 7.8
CVE-2024-50126 HIGH
Linux Kernel 6.1-6.6.58 - Use-After-Free in taprio_dump()
CVSS 7.8
CVE-2024-50125 HIGH
Linux Kernel 5.15-6.11.5 - Use-After-Free in Bluetooth SCO Socket Timeout Handler
CVSS 7.8
CVE-2024-50124 HIGH
Linux Kernel 6.0-6.1.114 - Use-After-Free in Bluetooth ISO Socket Timeout Handler
CVSS 7.8
CVE-2024-50121 HIGH
Linux Kernel 5.10.220-5.14.x - Use-After-Free in NFS Server Shutdown
CVSS 7.8
CVE-2024-50114 HIGH
Linux Kernel 6.11-6.11.5 - Use-After-Free in KVM vCPU Teardown
CVSS 7.8
CVE-2024-50106 HIGH
Linux Kernel 3.17-6.11.5 - Use-After-Free in NFSd State Management
CVSS 7.0
CVE-2024-38424 HIGH
Qualcomm FastConnect and AR8035 Firmware - Memory Corruption in GNSS HAL
CVSS 7.8
CVE-2024-38421 HIGH
Qualcomm FastConnect and QAM Firmware - Memory Corruption in GPU Driver
CVSS 7.8
CVE-2024-38419 HIGH
Qualcomm FastConnect and AR8035/CSRA6620/CSRA6640 Firmware - Memory Corruption
CVSS 7.8
CVE-2024-38415 HIGH
Qualcomm Firmware - Memory Corruption
CVSS 7.8
CVE-2024-33068 HIGH
Qualcomm WSA8845H and other Firmware - Denial of Service via MBSSID IE Beacon Frame Parsing
CVSS 7.5
CVE-2024-33033 MEDIUM
Qualcomm WSA8845H and Multiple Firmware - Use-After-Free via IOCTL Buffer Unmap
CVSS 6.7
CVE-2024-33029 MEDIUM
Snapdragon Auto 5G Modem-RF Gen 2 Firmware - Use-After-Free in PDR Handling
CVSS 6.7
CVE-2024-9826 HIGH
AutoCAD 2025 < 2025.1.1 - Use-After-Free via Malicious 3DM File Parsing
CVSS 7.8
CVE-2024-8595 HIGH
AutoCAD 2025 < 2025.1.1 - Use-After-Free via Malicious MODEL File Parsing
CVSS 7.8
CVE-2024-8590 HIGH
AutoCAD 2025 < 2025.1.1 - Use-After-Free via Malicious 3DM File Parsing
CVSS 7.8
CVE-2024-10488 HIGH
Google Chrome < 130.0.6723.92 - Use-After-Free in WebRTC
CVSS 8.8
CVE-2024-10459 HIGH
Firefox < 132 and ESR < 128.4/< 115.17 - Use-After-Free with Accessibility Enabled
CVSS 7.5
CVE-2024-50086 HIGH
Linux Kernel < 6.1.114 - Use-After-Free in SMB2 Session Handling
CVSS 7.0
CVE-2024-50085 MEDIUM
Linux Kernel 5.15.167-5.15.169 - Use-After-Free in mptcp_pm_nl_rm_addr_or_subflow
CVSS 5.5
Details
Vulnerabilities 7,537
Exploit Likelihood High