libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in
In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disc
A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers respons
A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS i
Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially
Liblisp through commit 4c65969 was discovered to contain a use-after-free vulnerability in void hash_destroy(hash_table_
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to a
A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could
In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privi
In dit_hal_ioctl of dit.c, there is a possible use after free due to a race condition. This could lead to local escalati
The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c
There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up op
A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allo
In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege
In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege
In imgsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege
In pda, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit
In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege
A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows a
A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Ke
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4,
Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the rendere
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially explo
Information exposure in DSP services due to improper handling of freeing memory
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue
A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-bas
A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports
The bluetooth HCI host layer logic not clearing a global reference to a state pointer after handling connection events m
Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction.
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Use After Free vulnerability that could l
Adobe Dimension version 3.4.6 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Ed
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Ed
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Lin
In bt driver, there is a thread competition leads to early release of resources to be accessed. This could lead to local
Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process.
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lea
In gpu device, there is a memory corruption due to a use after free. This could lead to local denial of service in kerne
A use-after-free flaw was found in the Linux kernel’s core dump subsystem. This flaw allows a local user to crash the sy
Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could lead to disclosure
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
A Use After Free vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows a
A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-componen
yasm v1.3.0 was discovered to contain a use after free via the function pp_getline at /nasm/nasm-pp.c. Note: Multiple th
yasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third p
yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at yasm/modules
Frequently Asked Questions
What is CWE-416?
CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-416?
There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.
How can I protect against CWE-416 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.
Detect CWE-416 Vulnerabilities
CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.
Get Started