A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Sec
vim is vulnerable to Use After Free
vim is vulnerable to Use After Free
vim is vulnerable to Use After Free
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Securit
On PTX Series and QFX10k Series devices with the "inline-jflow" feature enabled, a use after free weakness in the Packet
In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 1
In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. Th
An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset.
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vu
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vu
The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/p
The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.
An issue was discovered in the heapless crate before 0.6.1 for Rust. The IntoIter Clone implementation clones an entire
Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory
An issue was discovered in Barrier before 2.3.4. An unauthenticated attacker can cause a segmentation fault in the barri
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_scalar_func
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_aggregate_f
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_window_func
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_collation h
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. commit_hook has a
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. rollback_hook has
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. update_hook has a
An issue was discovered in the lru crate before 0.7.1 for Rust. The iterators have a use-after-free, as demonstrated by
An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_format_info can cause a use-after-free.
An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_context can cause a use-after-free.
An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-f
Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during a
arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass a
An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-pr
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) a
vim is vulnerable to Use After Free
A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then con
fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.6 and iPadOS 14.6. P
In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a
nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon
Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute,
A race between command submission and destroying the context can cause an invalid context being added to the list leads
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started