Use After Free

CWE-416 · 5 records · 2 with a public proof-of-concept

Records the NVD classes as Use After Free (CWE-416), highest CVSS first.

  1. CRITICAL 9.8CVE-2026-0163

    In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-56848

    A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.3CVE-2026-71226

    Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.1CVE-2026-11368public PoC

    The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf destroy callb

    zephyr

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.3CVE-2026-18785public PoC

    A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It i

    AI risk analysis on Exploit-DB.ai →