Weaknesses of type CWE-416

5,110 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-30549HIGHUnpatched extfs vulnerabilities are exploitable through suid-mode ApptainerEPSS 0.4%CVE-2025-57108CRITICALKitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability mEPSS 0.4%CVE-2025-49014MEDIUMjq heap use after free vulnerability in f_strflocaltimeEPSS 0.4%CVE-2025-66023MEDIUMNanoMQ has Use-After-Free of malformed bridging messageEPSS 0.4%CVE-2023-5197HIGHUse-after-free in Linux kernel's netfilter: nf_tables componentEPSS 0.4%CVE-2025-55118HIGHBMC Control-M/Agent memory corruption in SSL/TLS communicationEPSS 0.4%CVE-2026-53462MEDIUMImageMagick: Use-After-Free when allocation in CheckPrimitiveExtent failsEPSS 0.4%CVE-2026-82063MEDIUMUse-After-Free in MongoDB Server Cursor Management Component Leads to Denial of ServiceEPSS 0.4%CVE-2023-6932HIGHUse-after-free in Linux kernel's ipv4: igmp componentEPSS 0.4%CVE-2022-2453HIGHUse After Free in gpac/gpacEPSS 0.4%CVE-2026-14178MEDIUMopenGauss存在非法内存访问导致DoS漏洞EPSS 0.4%CVE-2024-30275HIGHAdobe Aero Beta has an arbitrary code execution vulnerability when parsing svg filesEPSS 0.4%CVE-2023-46246MEDIUMInteger Overflow in :history command in VimEPSS 0.4%CVE-2020-35506—A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handlinEPSS 0.4%CVE-2023-41071HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOEPSS 0.4%CVE-2023-22244HIGHAdobe Premiere Rush PSD files Use After Free Arbitrary code executionEPSS 0.4%CVE-2025-52910CRITICALAn issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 1480, 2400. A Use-AfterEPSS 0.4%CVE-2023-26349MEDIUMZDI-CAN-20218: Adobe Dimension USDZ File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-7926HIGHUse after free in PresentationAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbEPSS 0.4%CVE-2026-50046MEDIUMPossible heap use-after-free in an error path when a DoT forwarded query is jostled outEPSS 0.4%