Weaknesses of type CWE-416

5,079 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-37004HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2025-11677MEDIUMUse After Free in libwebsockets WebSocket serverEPSS 0.4%CVE-2025-21159HIGHIllustrator | Use After Free (CWE-416)EPSS 0.4%CVE-2026-79210HIGHUse after free in Audio in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer proEPSS 0.4%CVE-2026-87639HIGHUse after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process toEPSS 0.4%CVE-2026-85048HIGHUse after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to EPSS 0.4%CVE-2026-59184HIGHOpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB writeEPSS 0.4%CVE-2026-84349HIGHUse after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execEPSS 0.4%CVE-2026-79224HIGHUse after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to eEPSS 0.4%CVE-2021-0262MEDIUMJunos OS: QFX10002-60C: Use after free vulnerability found during static code analysisEPSS 0.4%CVE-2026-78983HIGHUse after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to executEPSS 0.4%CVE-2026-87648HIGHUse after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer proEPSS 0.4%CVE-2026-79054HIGHUse after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to eEPSS 0.4%CVE-2026-87524HIGHUse after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer procEPSS 0.4%CVE-2026-10887HIGHUse after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via maliciouEPSS 0.4%CVE-2026-87480HIGHUse after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potEPSS 0.4%CVE-2023-37575HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2023-37574HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2023-37576HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2023-44328MEDIUMZDI-CAN-21797: Adobe Bridge MP4 File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%