Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-416 · Use after freeDefinition on MITRE ↗Clear

93 results·Page 1 / 2

CVE-2026-68820
2026-08-11
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Microsoft

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CWE-416 · Use after free
Refsportal.msrc.microsoft.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-25
CVE-2010-0249
2026-05-20
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-416 · Use after free
Refslearn.microsoft.comnvd.nist.gov
Federal remediation due 2026-06-03
CVE-2020-9715
2026-04-13
Adobe Acrobat Use-After-Free Vulnerability
Adobe

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution

CWE-416 · Use after free
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2026-04-27
CVE-2026-5281
2026-04-01
Google Dawn Use-After-Free Vulnerability
Google

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
RefsThis vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2026-04-15
CVE-2023-43000
2026-03-05
Apple Multiple products Use-After-Free Vulnerability
Apple

Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption.

CWE-416 · Use after free
Refssupport.apple.comsupport.apple.comsupport.apple.comnvd.nist.gov
Federal remediation due 2026-03-26
CVE-2023-41974
2026-03-05
Apple iOS and iPadOS Use-After-Free Vulnerability
Apple

Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.

CWE-416 · Use after free
Refssupport.apple.comsupport.apple.comnvd.nist.gov
Federal remediation due 2026-03-26
CVE-2026-2441
2026-02-17
Google Chromium CSS Use-After-Free Vulnerability
Google

Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2026-03-10
CVE-2025-43529
2025-12-15
Apple Multiple Products Use-After-Free WebKit Vulnerability
Apple

Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-416 · Use after free
Refssupport.apple.comsupport.apple.comsupport.apple.comsupport.apple.comsupport.apple.comnvd.nist.gov
Federal remediation due 2026-01-05
CVE-2025-62221
2025-12-09
Microsoft Windows Use After Free Vulnerability
Microsoft

Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-12-30
CVE-2025-27038
2025-06-03
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

CWE-416 · Use after free
RefsPlease check with specific vendors (OEMs,) for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2025-06-24
CVE-2025-32709
2025-05-13
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Microsoft

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-06-03
CVE-2025-32701
2025-05-13
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Microsoft

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-06-03
CVE-2025-30400
2025-05-13
Microsoft Windows DWM Core Library Use-After-Free Vulnerability
Microsoft

Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-06-03
CVE-2025-29824
2025-04-08
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free VulnerabilityRansomware
Microsoft

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-04-29
CVE-2025-24983
2025-03-11
Microsoft Windows Win32k Use-After-Free Vulnerability
Microsoft

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-04-01
CVE-2025-24085
2025-01-29
Apple Multiple Products Use-After-Free Vulnerability
Apple

Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.

CWE-416 · Use after free
Refssupport.apple.comsupport.apple.comsupport.apple.comsupport.apple.comsupport.apple.comnvd.nist.gov
Federal remediation due 2025-02-19
CVE-2025-21335
2025-01-14
Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
Microsoft

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-02-04
CVE-2025-21334
2025-01-14
Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
Microsoft

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-02-04
CVE-2024-9680
2024-10-15
Mozilla Firefox Use-After-Free VulnerabilityRansomware
Mozilla

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

CWE-416 · Use after free
Refsmozilla.orgnvd.nist.gov
Federal remediation due 2024-11-05
CVE-2024-43047
2024-10-08
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.

CWE-416 · Use after free
Refsgit.codelinaro.orgnvd.nist.gov
Federal remediation due 2024-10-29
CVE-2024-38193
2024-08-13
Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-09-03
CVE-2024-38107
2024-08-13
Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-09-03
CVE-2024-36971
2024-08-07
Android Kernel Remote Code Execution Vulnerability
Android

Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS.

CWE-416 · Use after free
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-08-28
CVE-2012-4792
2024-07-23
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft

Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object.

CWE-416 · Use after free
Refslearn.microsoft.comnvd.nist.gov
Federal remediation due 2024-08-13
CVE-2022-2586
2024-06-26
Linux Kernel Use-After-Free Vulnerability
Linux

Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.

CWE-416 · Use after free
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2024-07-17
CVE-2024-4610
2024-06-12
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm

Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

CWE-416 · Use after free
Refsdeveloper.arm.comnvd.nist.gov
Federal remediation due 2024-07-03
CVE-2024-1086
2024-05-30
Linux Kernel Use-After-Free VulnerabilityRansomware
Linux

Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.

CWE-416 · Use after free
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-06-20
CVE-2024-4671
2024-05-13
Google Chromium Visuals Use-After-Free Vulnerability
Google

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2024-06-03
CVE-2023-33063
2023-12-05
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP.

CWE-416 · Use after free
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2023-12-26
CVE-2022-22071
2023-12-05
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Qualcomm

Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress.

CWE-416 · Use after free
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2023-12-26
CVE-2023-21608
2023-10-10
Adobe Acrobat and Reader Use-After-Free Vulnerability
Adobe

Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.

CWE-416 · Use after free
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2023-10-31
CVE-2023-4211
2023-10-03
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

CWE-416 · Use after free
Refsdeveloper.arm.comnvd.nist.gov
Federal remediation due 2023-10-24
CVE-2023-36802
2023-09-12
Microsoft Streaming Service Proxy Privilege Escalation Vulnerability
Microsoft

Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-10-03
CVE-2021-29256
2023-07-07
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm / Mali Graphics Processing Unit (GPU)

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.

CWE-416 · Use after free
Refsdeveloper.arm.comnvd.nist.gov
Federal remediation due 2023-07-28
CVE-2021-25394
2023-06-29
Samsung Mobile Devices Race Condition Vulnerability
Samsung

Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.

CWE-416 · Use after free
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2023-07-20
CVE-2016-9079
2023-06-22
Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
Mozilla

Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.

CWE-416 · Use after free
Refsmozilla.orgnvd.nist.gov
Federal remediation due 2023-07-13
CVE-2023-32373
2023-05-22
Apple Multiple Products WebKit Use-After-Free Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-416 · Use after free
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-06-12
CVE-2023-29336
2023-05-09
Microsoft Win32K Privilege Escalation Vulnerability
Microsoft

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-05-30
CVE-2019-8526
2023-04-17
Apple macOS Use-After-Free Vulnerability
Apple

Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation.

CWE-416 · Use after free
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-05-08
CVE-2023-28205
2023-04-10
Apple Multiple Products WebKit Use-After-Free Vulnerability
Apple

Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-416 · Use after free
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-05-01
CVE-2023-0266
2023-03-30
Linux Kernel Use-After-Free Vulnerability
Linux

Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.

CWE-416 · Use after free
Refsgit.kernel.orgnvd.nist.gov
Federal remediation due 2023-04-20
CVE-2022-38181
2023-03-30
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm / Mali Graphics Processing Unit (GPU)

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.

CWE-416 · Use after free
Refsdeveloper.arm.comnvd.nist.gov
Federal remediation due 2023-04-20
CVE-2022-3038
2023-03-30
Google Chromium Network Service Use-After-Free Vulnerability
Google

Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-416 · Use after free
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2023-04-20
CVE-2023-21674
2023-01-10
Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.

CWE-416 · Use after free
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-01-31
CVE-2021-25370
2022-11-08
Samsung Mobile Devices Memory Corruption Vulnerability
Samsung

Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369.

CWE-416 · Use after free
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2022-11-29
CVE-2019-8605
2022-06-27
Apple Multiple Products Use-After-Free Vulnerability
Apple

A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2016-0984
2022-05-25
Adobe Flash Player and AIR Use-After-Free Vulnerability
Adobe

Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2021-1048
2022-05-23
Android Kernel Use-After-Free Vulnerability
Android

Android kernel contains a use-after-free vulnerability that allows for privilege escalation.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-06-13
CVE-2021-0920
2022-05-23
Android Kernel Race Condition Vulnerability
Android

Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.

CWE-362CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-06-13
CVE-2019-5786
2022-05-23
Google Chrome Blink Use-After-Free Vulnerability
Google

Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.

CWE-416 · Use after free
Refsnvd.nist.gov
Federal remediation due 2022-06-13
Prev1 / 2Next