CWE-416
CVEs classified under CWE-416, newest first.
1092 CVEsRSS
CVE-2026-65343High· 7.5PoCA use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected system ter…
CVE-2026-65338Medium· 4.3⚖ disputedThe issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may le…
CVE-2026-64787Medium· 6.5⚖ disputedA use-after-free issue was addressed with improved memory management
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing ma…
CVE-2026-65341Medium· 5.4⚖ disputedThe issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously craft…
CVE-2026-50060High· 7.8A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered whil…
CVE-2026-50061High· 7.8A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered whil…
CVE-2026-73071Low· 3.3Vim is an open source, command line text editor
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing t…
GHSA-2q33-cf8w-7q23Critical· 9.8Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability
Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability
CVE-2026-70307High· 7.0Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-70311High· 7.8Microsoft Office Word Remote Code Execution Vulnerability
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-61361High· 7.0Windows DHCP Client Remote Code Execution Vulnerability
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
CVE-2026-62705High· 7.0Microsoft Brokering File System Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62693High· 7.0Windows MIDI Service Module Elevation of Privileges Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-61934High· 7.8Windows Bind Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-61927High· 7.0Windows Bind Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62779High· 7.8Windows Schannel Elevation of Privilege Vulnerability
Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.
CVE-2026-62748High· 7.0Windows Telephony Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62729High· 7.0Windows Telephony Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62724High· 7.0Windows Telephony Service Elevation of Privilege Vulnerability
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62723High· 7.0Windows Telephony Service Elevation of Privilege Vulnerability
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62893Critical· 9.8Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-62892High· 7.0Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-62819High· 8.1Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-62818High· 8.8Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
CVE-2026-62815Critical· 9.8Microsoft QUIC Remote Code Execution Vulnerability
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
CVE-2026-62795High· 8.8Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
CVE-2026-62787High· 7.5Windows DNS Server Remote Code Execution Vulnerability
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
CVE-2026-62774High· 7.0Windows Graphics Kernel Elevation of Privilege Vulnerability
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-62773High· 7.0Windows Kerberos Elevation of Privilege Vulnerability
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
CVE-2026-65657High· 7.8Microsoft Office Remote Code Execution Vulnerability
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.