Possible use-after-free issue due to a race condition while calling camera ioctl concurrently in Snapdragon Compute, Sna
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privile
In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the dri
In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the driv
In the Android kernel in the synaptics_dsx_htc touchscreen driver there is a possible use after free due to improper loc
In the Android kernel in the mnh driver there is a use after free due to improper locking. This could lead to escalation
In the Android kernel in the synaptics_dsx_htc touchscreen driver there is a possible out of bounds write due to a use a
In the Android kernel in the mnh driver there is possible memory corruption due to a use after free. This could lead to
In the Android kernel in the FingerTipS touchscreen driver there is a possible use-after-free due to improper locking. T
In the Bluetooth stack, there is a possible out of bounds write due to a use after free. This could lead to local escala
In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include
When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 a
A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap c
A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit hea
A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap c
An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application coul
In Binaryen 1.38.22, there is a use-after-free problem in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp. Remote
Use after free in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Phanto
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 20
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 20
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 20
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier ver
Adobe Bridge CC versions 9.0.2 have an use after free vulnerability. Successful exploitation could lead to information d
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier ver
An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitatio
Incorrect handling of frames in the VP8 parser in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to poten
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap c
In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob fu
GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.
Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in DocumentWriter::replaceDoc
Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen removing elements wit
Use after free in Blink in Google Chrome prior to 75.0.3770.90 allowed a remote attacker to potentially exploit heap cor
Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap co
Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corr
Use after free in IndexedDB in Google Chrome prior to 73.0.3683.86 allowed a remote attacker who had compromised the ren
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bou
An issue was discovered in the Linux kernel before 5.0.10. There is a use-after-free in the sound subsystem because card
In the Android kernel in the mnh driver there is a race condition due to insufficient locking. This could lead to a use-
In the Linux kernel before 5.3.11, there is a use-after-free bug that can be caused by a malicious USB device in the dri
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the driv
Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by cha
In parser/btorsmt2.c in Boolector 3.0.0, opening a specially crafted input file leads to a use after free in get_failed_
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daem
An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to by
An unprivileged user can issue a binder call and cause a system halt in Snapdragon Auto, Snapdragon Compute, Snapdragon
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Phanto
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started