Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-416

MITRE ↗

Use After Free

834
CRITICAL
5,751
HIGH
1,124
MEDIUM
88
LOW
7,832 CVEs · Page 17/157
8.1
CVE-2026-79027

Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code ins

8.1
CVE-2026-79039

Use after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to execute arbitrar

8.1
CVE-2026-79194

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute

8.0
CVE-2026-34332

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

8.0
CVE-2026-53256

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_c

8.0
CVE-2026-53357

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() v

8.0
CVE-2026-49169

Use after free in DNS Server allows an authorized attacker to execute code over a network.

7.8
CVE-2025-20780

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

7.8
CVE-2025-20781

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

7.8
CVE-2025-20799

In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege i

7.8
CVE-2026-21486

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below

7.8
CVE-2025-47339

Memory corruption while deinitializing a HDCP session.

7.8
CVE-2026-20971

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary c

7.8
CVE-2025-71071

In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: fix use-after-free on probe deferra

7.8
CVE-2025-71073

In the Linux kernel, the following vulnerability has been resolved: Input: lkkbd - disable pending work before freeing

7.8
CVE-2025-71075

In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal

7.8
CVE-2025-71099

In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_io

7.8
CVE-2025-10865

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of refe

7.8
CVE-2026-20822

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20858

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20859

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20861

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic

7.8
CVE-2026-20865

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20867

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic

7.8
CVE-2026-20870

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20871

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20873

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic

7.8
CVE-2026-20874

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic

7.8
CVE-2026-20877

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20918

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic

7.8
CVE-2026-20920

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20923

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20924

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-20950

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-21287

Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi

7.8
CVE-2025-71110

In the Linux kernel, the following vulnerability has been resolved: mm/slub: reset KASAN tag in defer_free() before acc

7.8
CVE-2025-13845

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious pro

7.8
CVE-2025-15062

Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote a

7.8
CVE-2026-22980

In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to

7.8
CVE-2026-22995

In the Linux kernel, the following vulnerability has been resolved: ublk: fix use-after-free in ublk_partition_scan_wor

7.8
CVE-2025-71162

In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-af

7.8
CVE-2026-23001

In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source

7.8
CVE-2026-23010

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzb

7.8
CVE-2026-23012

In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: remove call_control in inactive cont

7.8
CVE-2025-33217

NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successfu

7.8
CVE-2025-33220

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memor

7.8
CVE-2026-20411

In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of serv

7.8
CVE-2025-47358

Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inad

7.8
CVE-2025-47359

Memory Corruption when multiple threads simultaneously access a memory free API.

7.8
CVE-2025-47398

Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers

Frequently Asked Questions

What is CWE-416?

CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-416?

There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.

How can I protect against CWE-416 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.

Detect CWE-416 Vulnerabilities

CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.

Get Started