VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

952 CVEsRSS

CVE-2026-73512High· 7.5
yesterday

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream r…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-50572Medium· 5.9
yesterday

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can retain a stale request callback after a request is reject…

Sunlitenvoyproxy · envoyvia NVD
CVE-2026-73513High· 7.5
yesterday

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 codec accepts a response trailer HEADERS frame without END_STRE…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-94084Critical· 9.4
2d ago

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

MidnightOISF · SuricataEPSS 0.40%via NVD
CVE-2026-94055Low· 3.7
3d ago

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

SunlitExim · EximEPSS 0.31%via NVD
CVE-2026-88097High· 8.1
4d ago

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.22%via NVD
CVE-2026-93586Low· 2.9
4d ago

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a cra…

SunlitImageMagick · ImageMagickEPSS 0.11%via NVD
CVE-2026-93382High· 8.8
5d ago

Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.37%via NVD
CVE-2026-93374Critical· 9.6
5d ago

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Midnightgoogle · chromeEPSS 0.35%via NVD
CVE-2026-93373Critical· 9.6
5d ago

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)

Midnightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-92474Low· 3.3PoC
6d ago

A security flaw has been discovered in GPAC 26.08-DEV

A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attac…

TwilightEPSS 0.15%via NVD
CVE-2026-92473Low· 3.3PoC
6d ago

A vulnerability was identified in GPAC 26.08-DEV

A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to b…

TwilightEPSS 0.16%via NVD
CVE-2026-92472Low· 3.3PoC
6d ago

A vulnerability was determined in GPAC 26.08-DEV

A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The a…

TwilightEPSS 0.16%via NVD
CVE-2026-92627Medium· 4.6
6d ago

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

SunlitThe HDF Group · HDF5EPSS 0.22%via NVD
CVE-2026-19666High· 7.5
6d ago

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

TwilightISC · BIND 9EPSS 0.48%via NVD
CVE-2026-19662Medium· 5.9
6d ago

An attacker may be able to cause a `named` resolver to abort

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the …

SunlitISC · BIND 9EPSS 0.41%via NVD
CVE-2026-78227Medium· 6.5
6d ago

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retrans…

SunlitNLnet Labs · UnboundEPSS 0.27%via NVD
CVE-2026-82720Medium· 5.9
6d ago

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a d…

SunlitNLnet Labs · UnboundEPSS 0.29%via NVD
CVE-2026-85893High· 8.8
1w ago

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.68%via NVD
CVE-2026-91749Critical· 9.6
1w ago

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

MidnightGoogle · ChromeEPSS 0.33%via NVD
CVE-2026-91747Low· 3.1⚖ disputed
1w ago

Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page

Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-91745High· 8.8
1w ago

Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-91737High· 8.8
1w ago

Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-91736High· 8.8
1w ago

Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-91729Critical· 9.6
1w ago

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-91724High· 8.3
1w ago

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security seve…

Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-91722High· 8.8
1w ago

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Twilightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-91721High· 8.8
1w ago

Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Twilightgoogle · chromeEPSS 0.39%via NVD
CVE-2026-91718Critical· 9.6
1w ago

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Midnightgoogle · chromeEPSS 0.33%via NVD
CVE-2026-91716Critical· 9.6
1w ago

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Midnightgoogle · chromeEPSS 0.31%via NVD
CWE-416 vulnerabilities (CVEs) · VulnSea