Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in
In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix potential use-after-free in airoha
In the Linux kernel, the following vulnerability has been resolved: mm: fix a UAF when vma->mm is freed after vma->vm_r
In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_c
In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: unlink NAPIs from queues on error to op
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid panic in f2fs_evict_inode As sy
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid UAF in f2fs_sync_inode_meta() s
In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode use after free in ext4_end_io_rsv_w
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix UAF on sva unbind with pending IOPF
In the Linux kernel, the following vulnerability has been resolved: xen: fix UAF in dmabuf_exp_from_pages() [dma_buf_f
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF in panthor_gem_create_with_han
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix use-after-free in amdgpu_userq_susp
In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It
In the Linux kernel, the following vulnerability has been resolved: zloop: fix KASAN use-after-free of tag set When a
In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_
In the Linux kernel, the following vulnerability has been resolved: proc: use the same treatment to check proc_lseek as
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_st
In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix use-after-free in AARP proxy pr
In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of pri
In mbrain, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege
In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Make dma-fences compliant with the safe acc
In the Linux kernel, the following vulnerability has been resolved: habanalabs: fix UAF in export_dmabuf() As soon as
In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalatio
In the Linux kernel, the following vulnerability has been resolved: ftrace: Also allocate and copy hash for reading of
In the Linux kernel, the following vulnerability has been resolved: fs/buffer: fix use-after-free when call bh_read() h
In the Linux kernel, the following vulnerability has been resolved: io_uring/futex: ensure io_futex_wait() cleans up pr
In the Linux kernel, the following vulnerability has been resolved: media: ivsc: Fix crash at shutdown due to missing m
In the Linux kernel, the following vulnerability has been resolved: open_tree_attr: do not allow id-mapping changes wit
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally
Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapC
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all
Premiere Pro versions 25.3, 24.6.5 and earlier are affected by a Use After Free vulnerability that could result in arbit
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerabil
Substance3D - Modeler versions 1.22.2 and earlier are affected by a Use After Free vulnerability that could result in ar
In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: prevent potential UAF If we hit th
In the Linux kernel, the following vulnerability has been resolved: drm/hisilicon/hibmc: fix irq_request()'s irq name v
In the Linux kernel, the following vulnerability has been resolved: android: binder: stop saving a pointer to the VMA
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started