Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
In the Linux kernel, the following vulnerability has been resolved: ACPI: EC: clean up handlers on probe failure in acp
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Ser
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.
Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate priv
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges
Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.
Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-Af
In the Linux kernel, the following vulnerability has been resolved: atm: lec: fix use-after-free in sock_def_readable()
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an
Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Read scx_root under scx_cgroup_ops_rwsem
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to loc
Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained va
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer all
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Sto
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started