The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. PROCA allows a use-after-free and ar
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, t
Use after free issue when MAP and UNMAP calls at same time as data structure used my MAP may be freed by UNMAP function
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.295
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.295
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.295
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.295
An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bf
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system ru
In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local use
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of ser
Failure in buffer management while accessing handle for HDR blit when color modes not supported by display in Snapdragon
NULL exception due to accessing bad pointer while posting events on RT FIFO in Snapdragon Compute, Snapdragon Mobile, Sn
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 and iPadOS 13.5, m
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
In main of main.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of
Use after free issue in camera applications when used randomly over multiple operations due to pointer not set to NULL a
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, an
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, an
Adobe Bridge versions 10.0.1 and earlier version have an use after free vulnerability. Successful exploitation could lea
Adobe Bridge versions 10.0.1 and earlier version have an use after free vulnerability. Successful exploitation could lea
HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a use after free vulnerability. There is a condit
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory,
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory,
When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been a
Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Comput
Use after free issue while processing error notification from camx driver due to not properly releasing the sequence dat
DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed sp
In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local esc
In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead
A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9
Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c.
njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from t
u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the
u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max clien
u'During the error occurrence in capture request, the buffer is freed and later accessed causing the camera APP to fail
The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because s
An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged atta
An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro
In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could le
In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to l
In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to local escalation of pr
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which it may have the use-after-free vulnerabi
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started