Use After Free in GitHub repository vim/vim prior to 9.0.0789.
Use After Free in GitHub repository vim/vim prior to 9.0.0882.
Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
Windows Kernel Elevation of Privilege Vulnerability
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer
In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to loc
In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. Thi
In TBD of aud_hal_tunnel.c, there is a possible memory corruption due to a use after free. This could lead to local esca
In l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking. This could lead to local es
In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local es
Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a use after free behavior when decod
An issue was discovered in JerryScript commit a6ab5e9. There is an Use-After-Free in lexer_compare_identifier_to_string
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is us
Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_sv
MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), w
MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is
MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer()
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /s
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_typ
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /string
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, can cause
The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability.
Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to sen
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the rem
MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase
MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common
A Use After Free vulnerability in the Advanced Forwarding Toolkit (AFT) manager process (aftmand) of Juniper Networks Ju
io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent
Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install
Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially explo
Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap co
SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.
A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a cr
A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisio
An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the s
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEnti
The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display
The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vuln
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in vers
The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerabilit
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started