Weaknesses of type CWE-416

5,074 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-14432HIGHUse after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafEPSS 0.4%CVE-2026-79197HIGHUse after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crEPSS 0.4%CVE-2026-15107HIGHUse after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox viEPSS 0.4%CVE-2026-6318HIGHUse after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via aEPSS 0.4%CVE-2026-19560HIGHUse after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2026-19559HIGHUse after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a cEPSS 0.4%CVE-2026-85049HIGHUse after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a EPSS 0.4%CVE-2024-8821LOWPDF-XChange Editor U3D File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2022-42414LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.4%CVE-2025-8292HIGHUse after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption viaEPSS 0.4%CVE-2026-23657HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-7010HIGHUse after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.4%CVE-2026-0885MEDIUMUse-after-free in the JavaScript: GC componentEPSS 0.4%CVE-2025-47976HIGHWindows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-1144MEDIUMquickjs-ng quickjs Atomics Ops quickjs.c use after freeEPSS 0.4%CVE-2026-43731HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2026-43715HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, iOEPSS 0.4%CVE-2023-6270HIGHKernel: aoe: improper reference count leads to use-after-free vulnerabilityEPSS 0.4%CVE-2025-54103HIGHWindows Management Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2021-43753HIGHAdobe Lightroom TIF File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%