Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulne
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker
AUTOMGEN versions up to and including 8.0.0.7 (also referenced as 8.022) contain a vulnerability in that project file ha
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UA
Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM
Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, becaus
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPad
A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwri
Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap co
Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.
The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocati
A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Ma
In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection()
In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update earlier in sctp_sf_do_dupcook_
In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the sca
In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Do not call scsi_done() from srp_abort()
Memory corruption while processing MBSSID beacon containing several subelement IE.
In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_dst to RCU rules syz
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
In the Linux kernel, the following vulnerability has been resolved: tipc: skb_linearize the head skb when reassembling
In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryptio
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free There are two .ex
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix UAF when detecting digest errors We
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a use-after-free Fix the following use-
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability a
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_signal_cifsd
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_network_n
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in is_valid_oplock_b
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_lea
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_opl
In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from par
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in smb2_reconnect_server() Th
In the Linux kernel, the following vulnerability has been resolved: can: j1939: fix Use-after-Free, hold skb ref while
In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix conn use after free during resets
In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: destroy cm id before destroy qp to avoid
In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix iscsi_task use after free Commit
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix use-after-free in rdata->read_into_pages(
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix use-after-free due to delegation race A
In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) worki
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt In r
In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential glock use-after-free on unmount
In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic in XDP_TX action In the XD
In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix possible use-after-free in transport
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix possible use-after-free in transport
In the Linux kernel, the following vulnerability has been resolved: nvme: fix a possible use-after-free in controller r
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started