Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Ju
Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kern
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleav
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Version
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSourc
rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality
Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a net
When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-base
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_ev
Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to eng
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a use
NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing iss
Use after free in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may al
Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenti
Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.
Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.This issue affects
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File Sy
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race co
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been special
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privilege
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix slab-use-after-free in decode_session6 W
In the Linux kernel, the following vulnerability has been resolved: ASoC: lpass: Fix for KASAN use_after_free out of bo
A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The soft
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
DHCP Client Service Remote Code Execution Vulnerability
Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, F
Transient DOS may occur when multi-profile concurrency arises with QHS enabled.
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua
In the Linux kernel, the following vulnerability has been resolved: ref_tracker: implement use-after-free detection Wh
In the Linux kernel, the following vulnerability has been resolved: tpm: fix reference counting for struct tpm_chip Th
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
In the Linux kernel, the following vulnerability has been resolved: cdx: Fix possible UAF error in driver_override_show
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started