In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to
A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions <
3D Viewer Remote Code Execution Vulnerability
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
Windows GDI Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows GDI Elevation of Privilege Vulnerability
A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local priv
Use after free vulnerability exists in Kostac PLC Programming Software Version 1.6.11.0. Arbitrary code may be executed
A use-after-free issue was addressed with improved memory management. This issue is fixed in tvOS 17, iOS 17 and iPadOS
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr
A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege
Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Use After Free in GitHub repository vim/vim prior to v9.0.2010.
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A special
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14.1. An app m
In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code du
In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation
In Media Resource Manager, there is a possible local arbitrary code execution due to use after free. This could lead to
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr
Microsoft Excel Remote Code Execution Vulnerability
GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples functio
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free
Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by a Use After Free vulnerability that
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge
In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local es
Memory corruption in DSP Services during a remote call from HLOS to DSP.
The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to f
Adobe Illustrator versions 28.0 (and earlier) and 27.9 (and earlier) are affected by a Use After Free vulnerability that
Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by a Use After Free vulnerabilit
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr
A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege es
Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the r
A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allow
Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `
The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used
Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in lib
Use after free in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escal
In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 12
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to en
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started