Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-50153HIGHDesktop Window Manager Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2021-20226—A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of servicEPSS 0.4%CVE-2026-74937HIGHUse-after-free in the JavaScript: GC componentEPSS 0.4%CVE-2026-84123HIGHPrivilege escalation due to use-after-free in the Graphics: WebGPU componentEPSS 0.4%CVE-2024-34117HIGHAdobe Photoshop 2024 MPO File Parsing Use-After-Free vulnerabilityEPSS 0.4%CVE-2024-23142HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2023-38216MEDIUMZDI-CAN-21404: Adobe Bridge Font Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-21551HIGHMicrosoft Cryptographic Services Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-4725CRITICALSandbox escape due to use-after-free in the Graphics: Canvas2D componentEPSS 0.4%CVE-2026-21251HIGHCluster Client Failover (CCF) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-42364MEDIUMA use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evalEPSS 0.4%CVE-2025-0151HIGHZoom Apps - Use After FreeEPSS 0.4%CVE-2022-1198—A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by siEPSS 0.4%CVE-2023-42108HIGHPDF-XChange Editor EMF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-37355LOWKofax Power PDF JPG File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2018-14619MEDIUMA flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when eachEPSS 0.4%CVE-2026-53071HIGHBluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rspEPSS 0.4%CVE-2026-64783HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS TaEPSS 0.4%CVE-2023-21756HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-71847HIGHRuby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streamsEPSS 0.4%