A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.2 and iPadOS 14.2, m
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, t
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, tvOS
An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a
In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, liste
In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could lead to local escala
In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a us
Microsoft Excel Remote Code Execution Vulnerability
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska f
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leve
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their pr
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the
The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and C
In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-l
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lea
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which mig
A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be pr
An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the
An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lo
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_s
An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_fu
Use after free issue when importing a DMA buffer by using the CPU address of the buffer due to attachment is not cleaned
A CWE-416: Use after free vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in
In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local esc
In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local esc
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto
A use-after-free issue exists in the DGN file-reading procedure in the Drawings SDK (All versions prior to 2022.4) resul
In memory management driver, there is a possible out of bounds write due to a use after free. This could lead to local e
In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local esc
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started