Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r
Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had com
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#enc
Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implem
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP threa
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap u
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with u
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memo
Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary cod
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF cras
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke
Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed
Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to
Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitra
Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malic
Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbit
Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthoriz
Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the
Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install
Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute ar
Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arb
Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap cor
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed an attacker who convinced a user to i
Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for th
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a ne
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to poten
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to tr
A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attack
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-se
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six to
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Att
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows u
Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started