Threats Tagged 'cwe-416'
View all threats tagged with 'cwe-416'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-416'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-71847: CWE-416: Use After Free in ruby jsonCVE-2026-71847 0 CVE-2026-71847 is a use-after-free vulnerability in the Ruby JSON native C extension affecting versions from 2.20.0 up to but not including 2.21.2. The flaw occurs when the JSON::ResumableParser processes incomplete JSON input containing duplicate keys, leading to dereferencing of freed memory and potential process termination. This vulnerability has a high severity with a CVSS score of 8.7 and has been fixed in version 2.21.2. Join the discussion | CVE Database V5 | 08/07/2026, 18:31:28 UTC Added: 08/07/2026, 18:56:59 UTC |
CVE-2026-43632: CWE-416 Use After Free in ggml-org llama.cppCVE-2026-43632 0 llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_server.vocab directly on HTTP worker threads. Attackers can exploit a time-of-check-time-of-use race condition where the main thread destroys and frees vocab after the synchronization lock is released but before the handler finishes using it, causing a crash or potential code execution when --sleep-idle-seconds is configured. Join the discussion | CVE Database V5 | 08/07/2026, 00:31:18 UTC Added: 08/06/2026, 22:13:22 UTC |
CVE-2026-43631: CWE-416 Use After Free in ggml-org llama.cppCVE-2026-43631 0 llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerability by sending requests to affected endpoints while the server transitions to sleep mode, causing concurrent worker threads to dereference a freed vocab pointer that can be reclaimed with attacker-controlled data to achieve remote code execution. Join the discussion | CVE Database V5 | 08/07/2026, 00:31:18 UTC Added: 08/06/2026, 22:13:22 UTC |
CVE-2026-1289: CWE-416: Use After Free in Autodesk RevitCVE-2026-1289 0 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. Join the discussion | CVE Database V5 | 08/06/2026, 15:57:13 UTC Added: 08/06/2026, 22:13:21 UTC |
CVE-2026-56848: CWE-416 Use After Free in nodejs nodeCVE-2026-56848 0 A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. Join the discussion | CVE Database V5 | 08/04/2026, 15:57:24 UTC Added: 08/04/2026, 16:28:46 UTC |
CVE-2026-66315: CWE-416: Use After Free in Microsoft Microsoft Edge (Chromium-based)CVE-2026-66315 0 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Join the discussion | CVE Database V5 | 08/03/2026, 22:53:12 UTC Added: 08/03/2026, 23:19:24 UTC |
CVE-2026-62870: CWE-416: Use After Free in Microsoft Microsoft 365 Apps for EnterpriseCVE-2026-62870 0 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. Join the discussion | CVE Database V5 | 08/03/2026, 22:58:03 UTC Added: 08/03/2026, 23:19:24 UTC |
CVE-2026-69244: CWE-400: Uncontrolled Resource Consumption in aio-libs aiohttpCVE-2026-69244 0 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3. Join the discussion | CVE Database V5 | 08/03/2026, 20:50:59 UTC Added: 08/03/2026, 21:18:57 UTC |
CVE-2026-20473: CWE-416 Use After Free in MediaTek, Inc. MediaTek chipsetCVE-2026-20473 0 In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759. Join the discussion | CVE Database V5 | 08/03/2026, 02:05:26 UTC Added: 08/03/2026, 02:48:33 UTC |
CVE-2026-63035: CWE-416 Use After Free in o6 Automation open62541CVE-2026-63035 0 CVE-2026-63035 is a heap use-after-free vulnerability in the TransferSubscriptions service of the open62541 product by o6 Automation. It may allow an authenticated attacker to cause denial of service or potentially execute arbitrary code. The vulnerability affects versions 1.3.0, 1.4.0, and 1.5.0. The CVSS score is 8.1, indicating high severity. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 07/30/2026, 21:56:04 UTC Added: 07/30/2026, 22:23:10 UTC |
Showing 1 to 10 of 166 results