In the Linux kernel, the following vulnerability has been resolved: drm/xe/reg_sr: Remove register pool That pool impl
In the Linux kernel, the following vulnerability has been resolved: net: defer final 'struct net' free in netns dismant
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix race between element replace and
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF via mismatching bpf_prog/attachment RC
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern
In the Linux kernel, the following vulnerability has been resolved: powerpc/mm/fault: Fix kfence page fault reporting
In the Linux kernel, the following vulnerability has been resolved: brd: defer automatic disk creation until module ini
The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error ca
In the Linux kernel, the following vulnerability has been resolved: mISDN: fix possible use-after-free in HFC_cleanup()
The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a st
Remote Desktop Client Remote Code Execution Vulnerability
The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD
media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function
media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function a
Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_lin
gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src
Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same int
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p
fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.
cassandra-rs is a Cassandra (CQL) driver for Rust. Code that attempts to use an item (e.g., a row) returned by an iterat
Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid
Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_Unknown
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::Ge
Use After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation of this vulnerabilit
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection st
FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.
libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows atta
An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects
Microsoft Office Remote Code Execution Vulnerability
Xbox Wireless Adapter Remote Code Execution Vulnerability
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
Windows Deployment Services Remote Code Execution Vulnerability
Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the h
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after
Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap cor
In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable cras
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
Windows SMB Denial of Service Vulnerability
Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously fre
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in th
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix NULL ptr deref in crypto_aead_setk
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge
In the Linux kernel, the following vulnerability has been resolved: sh: intc: Fix use-after-free bug in register_intc_c
Windows Kernel Elevation of Privilege Vulnerability
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started