Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code ins
Use after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to execute arbitrar
Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_c
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() v
Use after free in DNS Server allows an authorized attacker to execute code over a network.
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege i
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
Memory corruption while deinitializing a HDCP session.
Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary c
In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: fix use-after-free on probe deferra
In the Linux kernel, the following vulnerability has been resolved: Input: lkkbd - disable pending work before freeing
In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal
In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_io
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of refe
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi
In the Linux kernel, the following vulnerability has been resolved: mm/slub: reset KASAN tag in defer_free() before acc
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious pro
Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote a
In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to
In the Linux kernel, the following vulnerability has been resolved: ublk: fix use-after-free in ublk_partition_scan_wor
In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-af
In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzb
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: remove call_control in inactive cont
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successfu
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memor
In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of serv
Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inad
Memory Corruption when multiple threads simultaneously access a memory free API.
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started