Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-51551HIGHFoxit PDF Reader AcroForm Signature Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-79039HIGHUse after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sEPSS 0.4%CVE-2024-11525HIGHIrfanView DXF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-78913HIGHUse after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outsideEPSS 0.4%CVE-2026-13787HIGHUse after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via maliEPSS 0.4%CVE-2026-79194HIGHUse after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outsiEPSS 0.4%CVE-2025-62504MEDIUMEnvoy Lua filter use-after-free when oversized rewritten response body causes crashEPSS 0.4%CVE-2026-13071HIGHServer-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process TerminationEPSS 0.4%CVE-2026-56434HIGHNGINX ngx_http_ssi_module vulnerabilityEPSS 0.4%CVE-2022-41663HIGHA vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamceEPSS 0.4%CVE-2024-0752MEDIUMA use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted iEPSS 0.4%CVE-2023-3567HIGHKernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to raceEPSS 0.4%CVE-2024-34100HIGHUse-After-Free vulnerability in the latest Adobe Acrobat Reader DC when open malicious PDF fileEPSS 0.4%CVE-2024-37007HIGHMultiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based productsEPSS 0.4%CVE-2023-4921HIGHUse-after-free in Linux kernel's net/sched: sch_qfq componentEPSS 0.4%CVE-2026-46523MEDIUMImageMagick: Use-After-Free in MSL decoder.EPSS 0.4%CVE-2019-3896HIGHA double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw fEPSS 0.4%CVE-2023-39198HIGHKernel: qxl: race condition leading to use-after-free in qxl_mode_dumb_create()EPSS 0.4%CVE-2025-53730HIGHMicrosoft Office Visio Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-36565HIGHMicrosoft Office Graphics Elevation of Privilege VulnerabilityEPSS 0.4%