Weaknesses of type CWE-416

5,110 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-22915HIGHA heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execEPSS 0.4%CVE-2026-81986HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-47918HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-47912HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-27283HIGHInDesign Desktop | Use After Free (CWE-416)EPSS 0.4%CVE-2026-81985HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-34696HIGHInDesign Desktop | Use After Free (CWE-416)EPSS 0.4%CVE-2026-79909HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-47921HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-47920HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-16367CRITICALSandbox escape due to invalid pointer in the Disability Access APIs componentEPSS 0.4%CVE-2021-23134HIGHLinux kernel llcp_sock_bind/connect use-after-freeEPSS 0.4%CVE-2026-3847HIGHMemory safety bugs fixed in Firefox 148.0.2EPSS 0.4%CVE-2026-10885HIGHUse after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crEPSS 0.4%CVE-2026-10896HIGHUse after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crEPSS 0.4%CVE-2023-53358HIGHksmbd: fix racy issue under cocurrent smb2 tree disconnectEPSS 0.4%CVE-2022-47946MEDIUMAn issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attackeEPSS 0.4%CVE-2026-26330MEDIUMEnvoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directlyEPSS 0.4%CVE-2026-93382HIGHUse after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via EPSS 0.4%CVE-2026-79247HIGHUse after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the rendereEPSS 0.4%