Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-416

MITRE ↗

Use After Free

834
CRITICAL
5,751
HIGH
1,124
MEDIUM
88
LOW
7,832 CVEs · Page 89/157
8.3
CVE-2023-21795

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

8.3
CVE-2023-38669

Use after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition.

8.3
CVE-2023-36741

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

8.1
CVE-2023-21679

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

8.1
CVE-2023-23404

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2022-48434

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in work

8.1
CVE-2023-29325

Windows OLE Remote Code Execution Vulnerability

8.1
CVE-2023-20893

The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malici

8.1
CVE-2023-3297

In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice

8.1
CVE-2023-38166

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41765

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41767

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41768

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41769

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41770

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41771

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41773

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41774

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-35628

Windows MSHTML Platform Remote Code Execution Vulnerability

7.9
CVE-2023-0266 KEV

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 i

7.8
CVE-2022-47093

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to heap use-after-free via filters/dmx_m2ts.c:470 in m2tsdmx_declare

7.8
CVE-2023-21551

Microsoft Cryptographic Services Elevation of Privilege Vulnerability

7.8
CVE-2023-21552

Windows GDI Elevation of Privilege Vulnerability

7.8
CVE-2023-21680

Windows Win32k Elevation of Privilege Vulnerability

7.8
CVE-2023-21724

Microsoft DWM Core Library Elevation of Privilege Vulnerability

7.8
CVE-2023-21734

Microsoft Office Remote Code Execution Vulnerability

7.8
CVE-2023-21735

Microsoft Office Remote Code Execution Vulnerability

7.8
CVE-2023-21747

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-21755

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-21773

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-21774

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-21784

3D Builder Remote Code Execution Vulnerability

7.8
CVE-2022-4696

There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If 

7.8
CVE-2022-3977

A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This i

7.8
CVE-2023-0358

Use After Free in GitHub repository gpac/gpac prior to 2.3.0-DEV.

7.8
CVE-2023-21608 KEV

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are

7.8
CVE-2021-33641

When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses

7.8
CVE-2022-42374

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us

7.8
CVE-2023-20920

In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local

7.8
CVE-2023-20925

In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. Thi

7.8
CVE-2023-20928

In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local es

7.8
CVE-2023-0240

There is a logic error in io_uring's implementation which can be used to trigger a use-after-free vulnerability leading

7.8
CVE-2023-22360

Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error han

7.8
CVE-2023-24581

A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions),

7.8
CVE-2023-21688

NT OS Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-21822

Windows Graphics Component Elevation of Privilege Vulnerability

7.8
CVE-2023-21808

.NET and Visual Studio Remote Code Execution Vulnerability

7.8
CVE-2023-22244

Adobe Premiere Rush version 2.6 (and earlier) is affected by a Use After Free vulnerability that could result in arbitra

7.8
CVE-2023-22246

Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Use After Free vulnerability that

7.8
CVE-2023-26544

In the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NT

Frequently Asked Questions

What is CWE-416?

CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-416?

There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.

How can I protect against CWE-416 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.

Detect CWE-416 Vulnerabilities

CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.

Get Started