Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap cor
Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exp
Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a
Use after free in UI in Google Chrome on Linux prior to 96.0.4664.93 allowed a remote attacker to potentially exploit he
Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the rend
Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploi
Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potenti
Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap
Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potenti
Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sand
Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install
Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affe
Lucet is a native WebAssembly compiler and runtime. There is a bug in the main branch of `lucet-runtime` affecting all v
When sending a socket event message to a user application, invalid information will be passed if socket is freed by othe
A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Aut
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon A
Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snap
Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdrag
Use after free can occur due to improper handling of response from firmware in Snapdragon Auto, Snapdragon Compute, Snap
Use-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snap
Improper handling of sensor HAL structure in absence of sensor can lead to use after free in Snapdragon Auto
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementati
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when
A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGT
In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This
In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-fr
A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an atta
An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault
In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This coul
In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1
A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could caus
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
A use after free issue has been identified in Fatek FvDesigner Version 1.5.76 and prior in the way the application proce
In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and
In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free. This could l
In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to loca
Windows Win32k Elevation of Privilege Vulnerability
Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in S
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10
An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_c
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started