A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.2 and
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related mod
UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af
Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap cor
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an
Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a cr
Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause
Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenti
Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially per
Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std
Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts whe
UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availabili
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequ
Possible kernel exceptions caused by reading and writing kernel heap data after free.
NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been free
In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: don't add folio to be freed to L
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix possible deadlock in rfcomm_sk_state
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix management of listener transports Curren
InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could lead to
In the Linux kernel, the following vulnerability has been resolved: dm thin: fix use-after-free crash in dm_sm_register
Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclo
Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could lead to disclosur
In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. Th
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - flush misc workqueue during device sh
In the Linux kernel, the following vulnerability has been resolved: qlcnic: prevent ->dcb use-after-free on qlcnic_dcb_
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.2, macOS
Format Plugins versions 1.1.1 and earlier are affected by a Use After Free vulnerability that could lead to memory expos
Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via
Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corru
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap c
Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit hea
Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially
A vulnerability classified as critical has been found in Open Asset Import Library Assimp up to 5.4.3. Affected is the f
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the funct
A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/j
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of
A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_pack
A flaw has been found in appneta tcpreplay up to 4.5.1. The affected element is the function fix_ipv6_checksums of the f
A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol
A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file s
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge
A vulnerability was determined in axboe fio up to 3.41. This impacts the function __parse_jobs_ini of the file init.c. E
A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of
An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation
A vulnerability was detected in Kamailio 5.5. The affected element is the function sr_push_yy_state of the file src/core
A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/ar
A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started