In the Linux kernel, the following vulnerability has been resolved: i3c: master: cdns: Fix use after free vulnerability
In the Linux kernel, the following vulnerability has been resolved: netfilter: Fix use-after-free in get_info() ip6tab
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
In the Linux kernel, the following vulnerability has been resolved: binder: fix node UAF in binder_add_freeze_work() I
In the Linux kernel, the following vulnerability has been resolved: btrfs: ref-verify: fix use-after-free after invalid
In the Linux kernel, the following vulnerability has been resolved: net: ieee802154: do not leave a dangling sk pointer
In the Linux kernel, the following vulnerability has been resolved: net: avoid potential UAF in default_operstate() sy
In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Fix UAF in blkcg_unpin_online() blkcg_
Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GP
A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI syst
Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to
Memory corruption when multiple listeners are being registered with the same file descriptor.
Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of
Memory corruption when IPC callback handle is used after it has been released during register callback by another thread
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IO
Memory corruption while handling the PDR in driver for getting the remote heap maps.
Memory corruption while processing IOCTL calls to unmap the buffers.
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can o
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
In __unregister_prot_hook and packet_release of af_packet.c, there is a possible use-after-free due to improper lock
Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability
A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox
A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This c
nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.
In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after f
Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap co
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: af_bluetooth: Fix deadlock Attemting to
Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corru
Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap cor
Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows r
Unified Automation UaGateway OPC UA Server Use-After-Free Denial-of-Service Vulnerability. This vulnerability allows rem
Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows r
Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows r
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.
Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap cor
Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corru
Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy
Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to instal
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and
When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a p
Windows Hyper-V Denial of Service Vulnerability
In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use after free. This co
Windows USB Generic Parent Driver Remote Code Execution Vulnerability
In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix uaf in pvr2_context_set_notify
Windows Kernel Elevation of Privilege Vulnerability
Use after free in the UEFI firmware of some Intel(R) Server M20NTP BIOS may allow a privileged user to potentially enabl
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started