Weaknesses of type CWE-416

5,103 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-0358HIGHUse After Free in gpac/gpacEPSS 0.4%CVE-2023-37577HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2026-22264HIGHSuricata detect/alert: heap-use-after-free on alert queue expansionEPSS 0.4%CVE-2023-37573HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2024-43472MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-28687MEDIUMImageMagick has a Heap Use-After-Free in ImageMagick MSL decoderEPSS 0.4%CVE-2024-11113HIGHUse after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process tEPSS 0.4%CVE-2026-18700MEDIUMUse-After-Free in MongoDB Geospatial Validation Leads to Denial of ServiceEPSS 0.4%CVE-2024-9959HIGHUse after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potEPSS 0.4%CVE-2026-57437LOWNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetimeEPSS 0.4%CVE-2026-57436LOWNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node typeEPSS 0.4%CVE-2022-1158—A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddEPSS 0.4%CVE-2025-1930HIGHAudioIPC StreamData could trigger a use-after-free in the Browser processEPSS 0.4%CVE-2022-1204—A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocoEPSS 0.4%CVE-2021-25394MEDIUMA use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radioEPSS 0.4%KEVCVE-2026-56960CRITICALIn multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilegEPSS 0.4%CVE-2022-42408LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.4%CVE-2025-21372HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-21860HIGHDsoftbus has a use after free vulnerabilityEPSS 0.4%CVE-2025-0072HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.4%