In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix use-after-free bugs in mt79
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix use-after-free bugs in mt79
In the Linux kernel, the following vulnerability has been resolved: powerpc/pgtable-frag: Fix bad page state in pte_fra
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: pci: fix possible use-after-free cau
In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: use generic driver_override infrastruc
In the Linux kernel, the following vulnerability has been resolved: s390/ap: use generic driver_override infrastructure
In the Linux kernel, the following vulnerability has been resolved: s390/cio: use generic driver_override infrastructur
In the Linux kernel, the following vulnerability has been resolved: vdpa: use generic driver_override infrastructure W
In the Linux kernel, the following vulnerability has been resolved: platform/wmi: use generic driver_override infrastru
In the Linux kernel, the following vulnerability has been resolved: PCI: use generic driver_override infrastructure Wh
In the Linux kernel, the following vulnerability has been resolved: fs/mbcache: cancel shrink work before destroying th
Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitr
In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free bugs in error paths
In the Linux kernel, the following vulnerability has been resolved: net: phonet: free phonet_device after RCU grace per
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free race in fastrpc_m
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user i
In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Fix UAF at snd_timer_user_params() At
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Forcibly close timer instances at clos
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix use-after-free on object
In the Linux kernel, the following vulnerability has been resolved: net: ibm: emac: Fix use-after-free during device re
In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: fix use-after-free on inexact bin in
In the Linux kernel, the following vulnerability has been resolved: ipv6: anycast: insert aca into global hash under id
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing f
In the Linux kernel, the following vulnerability has been resolved: erofs: fix use-after-free on sbi->sync_decompress
In the Linux kernel, the following vulnerability has been resolved: tee: optee: prevent use-after-free when the client
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix a use-after-free of the hci_con
In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using spe
A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.
In the Linux kernel, the following vulnerability has been resolved: drm/xe/eustall: Fix drm_dev_put called before strea
In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: free channels on probe error
In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix NTMP DMA use-after-free issue The
The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace,
Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary co
Use after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege e
Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-leve
Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-leve
Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-le
In the Linux kernel, the following vulnerability has been resolved: fhandle: fix UAF due to unlocked ->mnt_ns read in m
The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing s
The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a
The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the
Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the
When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland b
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under
After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the
When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie
The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started