A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could ha
A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's publ
A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_m
NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.
A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below versi
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
dpic 2021.01.01 has a Heap Use-After-Free in thedeletestringbox() function in dpic.y.
A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0.
A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0.
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for
In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure
Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vulnerability can cause
During garbage collection extra operations were performed on a object that should not be. This could have led to a poten
Multi-thread vulnerability in the idmap module. Successful exploitation of this vulnerability may cause features to perf
Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect avail
A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the q
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows r
Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to crea
ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over
Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sand
Windows Named Pipe Filesystem Elevation of Privilege Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach
A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel.
A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Li
Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable throu
A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This
A use-after-free flaw was found in mt7921_check_offload_capability in drivers/net/wireless/mediatek/mt76/mt7921/init.c i
A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue m
A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethe
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samb
Windows GDI Elevation of Privilege Vulnerability
A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call
Win32k Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
In multiple functions of WVDrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/p
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging
An issue was discovered in the Linux kernel through 6.3.8. A use-after-free was found in ravb_remove in drivers/net/ethe
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/u
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging
A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of Fr
Microsoft Office Graphics Elevation of Privilege Vulnerability
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started