Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-43632CRITICALllama.cpp b7492–b9060 Use-After-Free in Tokenization EndpointsEPSS 0.5%CVE-2022-3586MEDIUMA flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket bEPSS 0.5%CVE-2023-21680HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-26311MEDIUMEnvoy HTTP: filter chain execution on reset streams causing UAF crashEPSS 0.5%CVE-2025-0634MEDIUMUse After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.EPSS 0.5%CVE-2025-54588HIGHEnvoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faultsEPSS 0.5%CVE-2025-26648HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-62229HIGHXorg: xmayland: use-after-free in xpresentnotify structure creationEPSS 0.5%CVE-2025-4372HIGHUse after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crEPSS 0.5%CVE-2026-8336HIGHPost-authentication use-after-free error in $_internalJsEmit and mapreduce commandsEPSS 0.5%CVE-2023-30772MEDIUMThe Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proEPSS 0.5%CVE-2026-20870HIGHWindows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-41222HIGHmm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.EPSS 0.5%CVE-2023-42041HIGHPDF-XChange Editor Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-23884HIGHHeap-use-after-free in gdi_set_boundsEPSS 0.5%CVE-2026-23883HIGHHeap-use-after-free in update_pointer_newEPSS 0.5%CVE-2026-2789HIGHUse-after-free in the Graphics: ImageLib componentEPSS 0.5%CVE-2026-2787HIGHUse-after-free in the DOM: Window and Location componentEPSS 0.5%CVE-2024-5847HIGHUse after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.5%CVE-2024-5846HIGHUse after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.5%