Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code vi
Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised t
Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to poten
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR
Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thu
Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromi
Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit
Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attacker
FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attacker
In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Don't reference skb after sending to VIOS
In the Linux kernel, the following vulnerability has been resolved: net: atm: fix use after free in lec_send() The ->s
Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via net
Microsoft Excel Remote Code Execution Vulnerability
In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. Thi
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This
In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc
In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free.
In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This
In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add length check in indx_get_root This a
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: fix potential OF node use-after-free
Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may a
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af
Wasmi is a WebAssembly interpreter focused on constrained and embedded systems. In versions 0.41.0, 0.41.1, 0.42.0 throu
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Windows Remote Desktop Services Remote Code Execution Vulnerability
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
Use after free in Navigation in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit he
In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() n
In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() c
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started