Weaknesses of type CWE-416

5,110 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-11118HIGHUse after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2023-1989HIGHA use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove wiEPSS 0.4%CVE-2023-25893HIGHZDI-CAN-19539: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-47205MEDIUMEnvoy: ext_authz Use-After-Free during Stream Teardown with Per-Route OverridesEPSS 0.4%CVE-2025-59221HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-25894HIGHZDI-CAN-19543: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-26336HIGHZDI-CAN-20275: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-25899HIGHZDI-CAN-19522: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-26544HIGHIn the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sector size and mEPSS 0.4%CVE-2022-42374HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2024-20789HIGHZDI-CAN-24030: Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-91721HIGHUse after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside EPSS 0.4%CVE-2023-44436HIGHKofax Power PDF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-29841HIGHUniversal Print Management Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-44435HIGHKofax Power PDF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-86713HIGHPX4 Autopilot through 1.17.0 Use-After-Free in load_monEPSS 0.4%CVE-2026-14111HIGHUse after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extensiEPSS 0.4%CVE-2026-13805HIGHUse after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML EPSS 0.4%CVE-2026-8551HIGHUse after free in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UIEPSS 0.4%CVE-2026-8518HIGHUse after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%