In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent UAF in ip6_send_skb() syzbot reporte
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_wed: fix use-after-free panic in
An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference
Windows Graphics Component Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Excel Elevation of Privilege Vulnerability
In the Linux kernel, the following vulnerability has been resolved: netem: fix return value if duplicate enqueue fails
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: st: fix probed platform device ref count
In the Linux kernel, the following vulnerability has been resolved: drm/xe: prevent UAF around preempt fence The fence
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix a use-after-free when hitting errors ins
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After F
Illustrator versions 28.6, 27.9.5 and earlier are affected by a Use After Free vulnerability that could result in arbitr
In the Linux kernel, the following vulnerability has been resolved: dmaengine: altera-msgdma: properly free descriptor
In the Linux kernel, the following vulnerability has been resolved: VMCI: Fix use-after-free when removing resource in
In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF caused by offsets overwrite Binder
In the Linux kernel, the following vulnerability has been resolved: HID: amd_sfh: free driver_data after destroying hid
In the Linux kernel, the following vulnerability has been resolved: xen: privcmd: Fix possible access to a freed kirqfd
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix missing cleanup on rollforward recovery
In the Linux kernel, the following vulnerability has been resolved: ila: call nf_unregister_net_hooks() sooner syzbot
In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscac
In the Linux kernel, the following vulnerability has been resolved: ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object
In the Linux kernel, the following vulnerability has been resolved: sch/netem: fix use after free in netem_dequeue If
There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to repres
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp
In the Linux kernel, the following vulnerability has been resolved: tracing/timerlat: Only clear timer if a kthread exi
In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: axg-card: fix 'use-after-free' Buffer
A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A mali
Memory corruption while maintaining memory maps of HLOS memory.
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of co
Microsoft Excel Remote Code Execution Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar
Substance3D - Stager versions 3.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbi
Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free in bpf_uprobe_multi_link_at
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb.c: fix UAF of vma in hugetlb fault pathw
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid use-after-free in f2fs_stop_gc_t
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid OOB when system.data xattr changes unde
In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix possible UAF for bfqq->bic with mer
In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't return OOB skb in manage_oob(). syz
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: always wait for both firmware loading
In the Linux kernel, the following vulnerability has been resolved: net: seeq: Fix use after free vulnerability in ethe
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started