In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to
A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specia
A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web
A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and i
A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, tvOS 14.0, Saf
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-afte
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers
An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block b
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.3752
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.3752
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A s
Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a
SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG),
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstati
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos and Qualcomm chipsets) software
An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition wi
An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition wi
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is a rac
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aw
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a pot
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 1
An issue was discovered in the internment crate through 2020-05-28 for Rust. ArcIntern::drop has a race condition and re
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, in
In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a us
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
While trying to obtain datad ipc handle during DPL initialization, Heap use-after-free issue can occur if modem SSR occu
Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdra
Use after free issue occurs when camera access sensors data through direct report mode in Snapdragon Auto, Snapdragon Co
Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lea
Potential use-after-free heap error during Validate/Present calls on display HW composer in Snapdragon Auto, Snapdragon
Possible stack-use-after-scope issue in NFC usecase for card emulation in Snapdragon Auto, Snapdragon Industrial IOT, Sn
Use after free while processing eeprom query as there is a chance to not unlock mutex after error occurs in Snapdragon A
Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of
Possibility of use-after-free and double free because of not marking buffer as NULL after freeing can lead to dangling p
Possible use after free issue while CRM is accessing the link pointer from device private data due to lack of resource p
In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to
Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.294
Use after free issue occurs If the real device interface goes down and a route lookup is performed while sending a raw I
Use-after-free in graphics module due to destroying already queued syncobj in error case in Snapdragon Auto, Snapdragon
Memory use after free issue in audio due to lack of resource control in Snapdragon Auto, Snapdragon Compute, Snapdragon
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started