Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges loca
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty loc
Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_r
Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap co
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, an
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
Memory corruption while performing sensor register read operations.
Memory corruption while accessing a synchronization object during concurrent operations.
Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of pri
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitutio
Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince co
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started