This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.1.1
A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF
In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remot
Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT
Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT
Use-after-free vulnerability will occur if reset of the routing table encounters an invalid rule id while processing com
A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF fil
In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use after free issue. This could lead to local escalation
In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local
In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc.
In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local
A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code executio
Null pointer dereference occurs for channel context while opening glink channel in Snapdragon Auto, Snapdragon Consumer
Access to freed memory can happen while reading from diag driver due to use after free issue in Snapdragon Auto, Snapdra
Multiple open and close from multiple threads will lead camera driver to access destroyed session data pointer in Snapdr
Pointer dereference while freeing IFE resources due to lack of length check of in port resource. in Snapdragon Consumer
Protection is missing while accessing md sessions info via macro which can lead to use-after-free in Snapdragon Auto, Sn
VCFTools vcftools prior to version 0.1.15 is affected by: Use-after-free. The impact is: Denial of Service or possibly o
In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r349806, 11.3-RELEASE bef
An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-afte
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciou
In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may tr
An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gf
An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_f
In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrect
In AudioInputDescriptor::setClientActive of AudioInputDescriptor.cpp, there is possible memory corruption due to a use a
Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user
Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, an
The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-
In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible u
GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie
In Keymaster, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no
Use after free issue occurs If another instance of open for voice_svc node has been called from application without clos
Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.251
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.2072
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.4.1.168
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0
An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF. A specially craft
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started