Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-54899MEDIUMOj: Use-After-Free in Oj::Parser Symbol Key Cache ToggleEPSS 0.4%CVE-2023-2236HIGHUse-after-free in Linux kernel's Performance Events subsystemEPSS 0.4%CVE-2026-71847HIGHRuby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streamsEPSS 0.4%CVE-2026-54901MEDIUMOj: Use-After-Free in Oj::Parser array_class/hash_class GC MarkingEPSS 0.4%CVE-2023-39488HIGHPDF-XChange Editor TIF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-21855HIGHibmvnic: Don't reference skb after sending to VIOSEPSS 0.4%CVE-2022-2318—There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kerneEPSS 0.4%CVE-2022-0216—A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeateEPSS 0.4%CVE-2024-38136HIGHWindows Resource Manager PSM Service Extension Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-8639HIGHUse after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruptEPSS 0.4%CVE-2025-62408MEDIUMc-ares has a Use After Free vulnerability when connection is cleaned up after errorEPSS 0.4%CVE-2024-38158HIGHAzure IoT SDK Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-39491HIGHPDF-XChange Editor TIF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-79064CRITICALUse after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execuEPSS 0.4%CVE-2026-79129CRITICALUse after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to EPSS 0.4%CVE-2026-87609CRITICALUse after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the EPSS 0.4%CVE-2026-87526CRITICALUse after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially eEPSS 0.4%CVE-2026-87504CRITICALUse after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary EPSS 0.4%CVE-2023-43842HIGHIncorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated EPSS 0.4%CVE-2026-78133HIGHlibcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.EPSS 0.4%