Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-416

MITRE ↗

Use After Free

834
CRITICAL
5,751
HIGH
1,124
MEDIUM
88
LOW
7,832 CVEs · Page 57/157
7.0
CVE-2025-59195

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon

7.0
CVE-2025-59196

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allo

7.0
CVE-2025-59202

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-59221

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-59282

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows

7.0
CVE-2025-59515

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-60716

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-60717

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-62213

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2025-62555

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-62569

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-62573

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-68617

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a rac

6.7
CVE-2024-33055

Memory corruption while invoking IOCTL calls to unmap the DMA buffers.

6.7
CVE-2024-33059

Memory corruption while processing frame command IOCTL calls.

6.7
CVE-2024-49848

Memory corruption while processing multiple IOCTL calls from HLOS to DSP.

6.7
CVE-2025-26681

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

6.7
CVE-2025-49743

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon

6.7
CVE-2025-20707

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil

6.7
CVE-2025-20770

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20772

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20773

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20775

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-66326

Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect avail

6.7
CVE-2025-55308

An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing

6.7
CVE-2025-55309

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF

6.7
CVE-2025-36922

In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to loc

6.6
CVE-2024-38411

Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.

6.6
CVE-2024-38412

Memory corruption while invoking IOCTL calls from user-space to kernel-space to handle session errors.

6.6
CVE-2024-45540

Memory corruption while invoking IOCTL map buffer request from userspace.

6.6
CVE-2024-45544

Memory corruption while processing IOCTL calls to add route entry in the HW.

6.6
CVE-2024-45562

Memory corruption during concurrent access to server info object due to unprotected critical field.

6.6
CVE-2024-45583

Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.

6.6
CVE-2024-53015

Memory corruption while processing IOCTL command to handle buffers associated with a session.

6.6
CVE-2025-53185

Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access re

6.5
CVE-2025-3028

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulner

6.5
CVE-2025-1704

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users

6.5
CVE-2025-27365

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0,

6.5
CVE-2025-23104

An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privi

6.5
CVE-2025-23101

An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privi

6.5
CVE-2025-23106

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo

6.5
CVE-2025-3631

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process termi

6.5
CVE-2025-43216

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and i

6.5
CVE-2025-62504

Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain

6.5
CVE-2025-57109

Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When pr

6.5
CVE-2025-29699

NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

6.5
CVE-2025-43457

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and i

6.5
CVE-2025-54335

An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-afte

6.5
CVE-2025-65405

A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows

6.5
CVE-2025-65407

A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows atta

Frequently Asked Questions

What is CWE-416?

CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-416?

There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.

How can I protect against CWE-416 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.

Detect CWE-416 Vulnerabilities

CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.

Get Started