Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al
An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.
Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locall
A vulnerability was found in PX4 PX4-Autopilot up to 1.15.4. This issue affects the function MavlinkReceiver::handle_mes
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free.
UAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerability may cause servi
Pointer dangling vulnerability in the cjwindow module. Impact: Successful exploitation of this vulnerability may affect
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and i
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, i
Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadO
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and i
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:red
In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of pri
In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privil
In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege
Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in
Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u
A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_f
Tungsten Automation Power PDF JP2 File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability a
A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulner
PDF-XChange Editor U3D File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remot
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_li
Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bou
In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.
A vulnerability, which was classified as problematic, has been found in Radare2 5.9.9. Affected by this issue is the fun
rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_prot
XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, th
c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when
There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using t
There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/
jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_s
pycares is a Python module which provides an interface to c-ares. c-ares is a C library that performs DNS requests and n
The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creatio
It is possible to cause an use-after-free write in SANM decoding with a carefully crafted animation using subversion <2.
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started