CWE-416 · 8,147 records
Use after free
Why does it happen?
After a memory region is freed, another reference pointing to it is still used. By then, the same region may have been allocated for different data.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
free(dev->buf);/* ... another thread is still running ... */process(dev->buf);Fixed
lock(&dev->lock);free(dev->buf);dev->buf = NULL;unlock(&dev->lock);How to prevent it
- 01Set the freed pointer to NULL immediately.
- 02Use reference counting and locks for shared objects.
- 03Test with memory error detectors (sanitizers).
CVEs in this class
8,211 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2019-0708Weaponized | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attackermicrosoft · windows 7 · CWE-416 | Critical9.8 | KEV | 100.0% | May 16, 2019 |
99Now | CVE-2021-31166Weaponized | HTTP Protocol Stack Remote Code Execution Vulnerabilitymicrosoft · windows 10 2004 · CWE-416 | Critical9.8 | KEV | 99.9% | May 11, 2021 |
99Now | CVE-2015-5119Weaponized | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Critical9.8 | KEV | 99.3% | Jul 8, 2015 |
98Now | CVE-2015-0313Weaponized | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Critical9.8 | KEV | 95.3% | Feb 2, 2015 |
97Now | CVE-2015-5122Weaponized | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Critical9.8 | KEV | 94.0% | Jul 14, 2015 |
94Now | CVE-2020-3992Weaponized | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a vmware · cloud foundation · CWE-416 | Critical9.8 | KEV | 83.0% | Oct 20, 2020 |
94Now | CVE-2014-1776Weaponized | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denialmicrosoft · internet explorer · CWE-416 | Critical9.8 | KEV | 82.7% | Apr 27, 2014 |
93Now | CVE-2010-0249Weaponized | Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2microsoft · internet explorer · CWE-416 | High8.8 | KEV | 91.9% | Jan 15, 2010 |
91Now | CVE-2010-3962Weaponized | Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors relatemicrosoft · internet explorer · CWE-416 | High8.1 | KEV | 96.8% | Nov 5, 2010 |
91Now | CVE-2013-3893Weaponized | Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote amicrosoft · internet explorer · CWE-416 | High8.8 | KEV | 87.5% | Sep 18, 2013 |
91Now | CVE-2014-0322Weaponized | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involvingmicrosoft · internet explorer · CWE-416 | High8.8 | KEV | 85.1% | Feb 14, 2014 |
89Now | CVE-2021-26411Weaponized | Internet Explorer Memory Corruption Vulnerabilitymicrosoft · edge · CWE-416 | High8.8 | KEV | 80.8% | Mar 11, 2021 |
89Now | CVE-2012-4792Weaponized | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web microsoft · internet explorer · CWE-416 | High8.8 | KEV | 78.8% | Dec 30, 2012 |
88Now | CVE-2018-15982Weaponized | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.adobe · flash player · CWE-416 | High7.8 | KEV | 89.6% | Jan 18, 2019 |
88Now | CVE-2018-4878Weaponized | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.adobe · flash player · CWE-416 | High7.8 | KEV | 89.5% | Feb 6, 2018 |
88Now | CVE-2013-1347Weaponized | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessimicrosoft · internet explorer · CWE-416 | High8.8 | KEV | 77.7% | May 5, 2013 |
88Now | CVE-2013-3897Weaponized | Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers microsoft · internet explorer · CWE-416 | High8.8 | KEV | 77.3% | Oct 9, 2013 |
87Now | CVE-2013-2551Weaponized | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted webmicrosoft · internet explorer · CWE-416 | High8.8 | KEV | 74.1% | Mar 11, 2013 |
86Now | CVE-2016-9079Weaponized | A use-after-free vulnerability in SVG Animation has been discovered.debian · debian linux · CWE-416 | High7.5 | KEV | 87.4% | Jun 11, 2018 |
86Now | CVE-2020-0674Weaponized | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripmicrosoft · internet explorer · CWE-416 | High7.5 | KEV | 86.9% | Feb 11, 2020 |
86Now | CVE-2009-4324Weaponized | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before adobe · acrobat · CWE-416 | High7.8 | KEV | 81.9% | Dec 14, 2009 |
86Now | CVE-2012-4969Weaponized | Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackermicrosoft · internet explorer · CWE-416 | High8.1 | KEV | 80.3% | Sep 18, 2012 |
84Now | CVE-2017-0261Weaponized | Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly microsoft · office · CWE-416 | High7.8 | KEV | 78.1% | May 12, 2017 |
83Now | CVE-2019-1429Weaponized | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripmicrosoft · internet explorer · CWE-416 | High7.5 | KEV | 77.3% | Nov 12, 2019 |
83Now | CVE-2021-40449Weaponized | Win32k Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-416 | High7.8 | KEV | 74.1% | Oct 12, 2021 |
- CVE-2019-070899Now
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · windows 7May 16, 2019
- CVE-2021-3116699Now
HTTP Protocol Stack Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · windows 10 2004May 11, 2021
- CVE-2015-511999Now
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
CriticalCVSS 9.8KEVWeaponizedEPSS 99%adobe · flash playerJul 8, 2015
- CVE-2015-031398Now
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
CriticalCVSS 9.8KEVWeaponizedEPSS 95%adobe · flash playerFeb 2, 2015
- CVE-2015-512297Now
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · flash playerJul 14, 2015
- CVE-2020-399294Now
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a
CriticalCVSS 9.8KEVWeaponizedEPSS 83%vmware · cloud foundationOct 20, 2020
- CVE-2014-177694Now
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial
CriticalCVSS 9.8KEVWeaponizedEPSS 83%microsoft · internet explorerApr 27, 2014
- CVE-2010-024993Now
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2
HighCVSS 8.8KEVWeaponizedEPSS 92%microsoft · internet explorerJan 15, 2010
- CVE-2010-396291Now
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors relate
HighCVSS 8.1KEVWeaponizedEPSS 97%microsoft · internet explorerNov 5, 2010
- CVE-2013-389391Now
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote a
HighCVSS 8.8KEVWeaponizedEPSS 88%microsoft · internet explorerSep 18, 2013
- CVE-2014-032291Now
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving
HighCVSS 8.8KEVWeaponizedEPSS 85%microsoft · internet explorerFeb 14, 2014
- CVE-2021-2641189Now
Internet Explorer Memory Corruption Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 81%microsoft · edgeMar 11, 2021
- CVE-2012-479289Now
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web
HighCVSS 8.8KEVWeaponizedEPSS 79%microsoft · internet explorerDec 30, 2012
- CVE-2018-1598288Now
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability.
HighCVSS 7.8KEVWeaponizedEPSS 90%adobe · flash playerJan 18, 2019
- CVE-2018-487888Now
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161.
HighCVSS 7.8KEVWeaponizedEPSS 90%adobe · flash playerFeb 6, 2018
- CVE-2013-134788Now
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessi
HighCVSS 8.8KEVWeaponizedEPSS 78%microsoft · internet explorerMay 5, 2013
- CVE-2013-389788Now
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers
HighCVSS 8.8KEVWeaponizedEPSS 77%microsoft · internet explorerOct 9, 2013
- CVE-2013-255187Now
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web
HighCVSS 8.8KEVWeaponizedEPSS 74%microsoft · internet explorerMar 11, 2013
- CVE-2016-907986Now
A use-after-free vulnerability in SVG Animation has been discovered.
HighCVSS 7.5KEVWeaponizedEPSS 87%debian · debian linuxJun 11, 2018
- CVE-2020-067486Now
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip
HighCVSS 7.5KEVWeaponizedEPSS 87%microsoft · internet explorerFeb 11, 2020
- CVE-2009-432486Now
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before
HighCVSS 7.8KEVWeaponizedEPSS 82%adobe · acrobatDec 14, 2009
- CVE-2012-496986Now
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attacker
HighCVSS 8.1KEVWeaponizedEPSS 80%microsoft · internet explorerSep 18, 2012
- CVE-2017-026184Now
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly
HighCVSS 7.8KEVWeaponizedEPSS 78%microsoft · officeMay 12, 2017
- CVE-2019-142983Now
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip
HighCVSS 7.5KEVWeaponizedEPSS 77%microsoft · internet explorerNov 12, 2019
- CVE-2021-4044983Now
Win32k Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 74%microsoft · windows 10 1507Oct 12, 2021