Tanium addressed a use-after-free vulnerability in the Cloud Workloads Enforce client extension.
Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rend
dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handl
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c.
In MAE, there is a possible system crash due to use after free. This could lead to local denial of service if a maliciou
In imgsys, there is a possible system crash due to use after free. This could lead to local denial of service if a malic
In display, there is a possible system crash due to use after free. This could lead to local denial of service if a mali
Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function durin
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, mac
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out o
A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function discover_handler in t
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.1
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Ta
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurre
Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_
Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.3
Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect avai
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the pac
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails
ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when me
ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory alloca
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initializati
The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read
A vulnerability was identified in FascinatedBox lily up to 2.3. Affected by this issue is the function shorthash_for_nam
A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the f
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the funct
A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/co
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can reta
UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect ava
Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendere
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure
A vulnerability was detected in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::opera
A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alph
A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCK
Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: D
Use After Free vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). This vulnerabili
Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Ke
Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-Aft
Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to 3.17.2, Oj::Doc iterators (e
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started