CWE-416
Use After Free
Description
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (8,218)
page 150 of 411| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62711 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62707 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62701 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61934 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61357 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61349 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50061 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files.… | ||
| CVE-2026-50060 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files.… | ||
| CVE-2026-1289 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2026 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. | ||
| CVE-2026-17862 | Hig | 0.51 | 7.8 | 0.00 | Jul 30, 2026 | Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) | ||
| CVE-2026-49743 | Hig | 0.51 | 7.8 | 0.00 | Jul 24, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference… | ||
| CVE-2026-15905 | Hig | 0.51 | 7.8 | 0.00 | Jul 20, 2026 | Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High) | ||
| CVE-2026-34196 | Hig | 0.51 | 7.8 | 0.00 | Jul 10, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow and map two GPU virtual addresses to the same physical address. One of these virutal mappings can be freed along with the physical page, allowing for a… | ||
| CVE-2026-42958 | — | Hig | 0.51 | 7.8 | 0.00 | Jul 7, 2026 | The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This could allow an attacker to execute arbitrary code in the context of the current process. | |
| CVE-2026-14094 | Hig | 0.51 | 7.8 | 0.00 | Jun 30, 2026 | Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low) | ||
| CVE-2026-14018 | Hig | 0.51 | 7.8 | 0.00 | Jun 30, 2026 | Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) | ||
| CVE-2026-13844 | Hig | 0.51 | 7.8 | 0.00 | Jun 30, 2026 | Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High) | ||
| CVE-2026-13827 | Hig | 0.51 | 7.8 | 0.00 | Jun 30, 2026 | Use after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High) | ||
| CVE-2026-13778 | Hig | 0.51 | 7.8 | 0.00 | Jun 30, 2026 | Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical) | ||
| CVE-2026-12921 | Hig | 0.51 | 7.8 | 0.00 | Jun 25, 2026 | In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution. |
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files.…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files.…
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
- risk 0.51cvss 7.8epss 0.00
Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
- risk 0.51cvss 7.8epss 0.00
Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference…
- risk 0.51cvss 7.8epss 0.00
Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
- risk 0.51cvss 7.8epss 0.00
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow and map two GPU virtual addresses to the same physical address. One of these virutal mappings can be freed along with the physical page, allowing for a…
- risk 0.51cvss 7.8epss 0.00
The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This could allow an attacker to execute arbitrary code in the context of the current process.
- risk 0.51cvss 7.8epss 0.00
Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)
- risk 0.51cvss 7.8epss 0.00
Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
- risk 0.51cvss 7.8epss 0.00
Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
- risk 0.51cvss 7.8epss 0.00
Use after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
- risk 0.51cvss 7.8epss 0.00
Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)
- risk 0.51cvss 7.8epss 0.00
In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.