CWE-416
Use After Free
Description
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (8,192)
page 283 of 410| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20842 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20830 | Hig | 0.46 | 7.0 | 0.00 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-20779 | Hig | 0.46 | 7.0 | 0.00 | Jan 6, 2026 | In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184084; Issue ID: MSV-4720. | ||
| CVE-2025-48769 | Hig | 0.46 | 8.1 | 0.02 | Jan 1, 2026 | Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to the previously freed… | ||
| CVE-2025-62573 | Hig | 0.46 | 7.0 | 0.00 | Dec 9, 2025 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-62569 | Hig | 0.46 | 7.0 | 0.00 | Dec 9, 2025 | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-62555 | Hig | 0.46 | 7.0 | 0.01 | Dec 9, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-62213 | Hig | 0.46 | 7.0 | 0.02 | Nov 11, 2025 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-60717 | Hig | 0.46 | 7.0 | 0.00 | Nov 11, 2025 | Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-60716 | Hig | 0.46 | 7.0 | 0.00 | Nov 11, 2025 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59515 | Hig | 0.46 | 7.0 | 0.00 | Nov 11, 2025 | Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59282 | Hig | 0.46 | 7.0 | 0.01 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-59221 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-59202 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59196 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59195 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally. | ||
| CVE-2025-58738 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58737 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58736 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-58735 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184084; Issue ID: MSV-4720.
- risk 0.46cvss 8.1epss 0.02
Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to the previously freed…
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.02
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.