In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free when attempting to join a
In the Linux kernel, the following vulnerability has been resolved: vsock: Keep the binding until socket destruction P
In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: extend RCU protection in igmp6_send()
In the Linux kernel, the following vulnerability has been resolved: openvswitch: use RCU protection in ovs_vport_cmd_fi
In the Linux kernel, the following vulnerability has been resolved: neighbour: use RCU protection in __neigh_notify()
In the Linux kernel, the following vulnerability has been resolved: ndisc: use RCU protection in ndisc_alloc_skb() ndi
In the Linux kernel, the following vulnerability has been resolved: workqueue: Put the pwq after detaching the rescuer
In the Linux kernel, the following vulnerability has been resolved: vrf: use RCU protection in l3mdev_l3_out() l3mdev_
In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Add missing delayed work cancel
In the Linux kernel, the following vulnerability has been resolved: memory: tegra20-emc: fix an OF node reference bug i
In the Linux kernel, the following vulnerability has been resolved: nilfs2: protect access to buffers with no active re
In the Linux kernel, the following vulnerability has been resolved: ax25: rcu protect dev->ax25_ptr syzbot found a loc
Memory corruption while processing command in Glink linux.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound mode
Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
Memory corruption may occur while accessing a variable during extended back to back tests.
Memory corruption while calling the NPU driver APIs concurrently.
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject struct_ops registration that uses modul
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: remove unused check_buddy_priv Comm
In the Linux kernel, the following vulnerability has been resolved: KVM: Explicitly verify target vCPU is online in kvm
Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.
A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualizat
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerabil
Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerabil
Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerabil
Substance3D - Modeler versions 1.15.0 and earlier are affected by a Use After Free vulnerability that could result in ar
Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remot
In the Linux kernel, the following vulnerability has been resolved: s390/ism: add release function for struct device A
In the Linux kernel, the following vulnerability has been resolved: geneve: Fix use-after-free in geneve_find_dev(). s
A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malici
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can
In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_fin
Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.
Luxion KeyShot USDC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote at
In the Linux kernel, the following vulnerability has been resolved: bpf, test_run: Fix use-after-free issue in eth_skb_
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free on inode when scanning ro
In the Linux kernel, the following vulnerability has been resolved: ice: Fix deinitializing VF in error path If ice_en
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started