Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-42040HIGHPDF-XChange Editor mailForm Use-After-Free Code Execution VulnerabilityEPSS 0.5%CVE-2023-42059HIGHPDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-53185HIGHsmb: client: fix NULL ptr deref in crypto_aead_setkey()EPSS 0.5%CVE-2024-0807HIGHUse after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.5%CVE-2023-42086HIGHPDF-XChange Editor EMF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-81934HIGHRedis TLS pending-data list use-after-freeEPSS 0.5%CVE-2024-36013HIGHBluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()EPSS 0.5%CVE-2026-68886MEDIUMWindows Network Connection Broker Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-32712HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-38428MEDIUMAdobe Photoshop DCM File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-58735HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-23135HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.5%CVE-2025-58732HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-34263HIGHAdobe Illustrator Font Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-8637HIGHUse after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corEPSS 0.5%CVE-2026-74969HIGHUse-after-free in the Layout: Text and Fonts componentEPSS 0.5%CVE-2024-50086CRITICALksmbd: fix user-after-free from session log offEPSS 0.5%CVE-2024-6774HIGHUse after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specifEPSS 0.5%CVE-2022-3314MEDIUMUse after free in logging in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentialEPSS 0.5%CVE-2026-43632CRITICALllama.cpp b7492–b9060 Use-After-Free in Tokenization EndpointsEPSS 0.5%