Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a sta
When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property arr
Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allo
An issue was discovered in the diesel crate before 1.4.6 for Rust. There is a use-after-free in the SQLite backend becau
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption a
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSS
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously cra
HTTP Protocol Stack Remote Code Execution Vulnerability
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early.
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the noti
aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.
There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0
A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a
In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-2542
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vu
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone.Successful exploitation of this vul
OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, w
A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snap
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to
Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and
There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to
An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A patch operation may result in a use-after-f
Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the rendere
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised t
Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the rend
Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the ren
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compr
Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the render
Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the ren
Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform
User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised t
Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromis
Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perfo
Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attack
Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perfo
Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the r
Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had comprom
Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sa
Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the r
Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the re
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised th
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the rende
Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbo
Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started