Weaknesses of type CWE-416

5,110 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-33069HIGHUse After Free in WLAN HostEPSS 0.4%CVE-2025-53133HIGHWindows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-20679MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. ProcessingEPSS 0.4%CVE-2022-50386HIGHBluetooth: L2CAP: Fix user-after-freeEPSS 0.4%CVE-2022-49114HIGHscsi: libfc: Fix use after free in fc_exch_abts_resp()EPSS 0.4%CVE-2023-21584MEDIUMAdobe FrameMaker Font Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-53140HIGHWindows Kernel Transaction Manager Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-50167HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-53721HIGHWindows Connected Devices Platform Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2022-1882—A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notifiEPSS 0.4%CVE-2026-91957LOWFreeRDP before 3.31.0 Use-After-Free via smartcard workerEPSS 0.4%CVE-2026-11054HIGHUse after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2024-3299HIGHOut-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the SLDDRW and SLDPRT file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024EPSS 0.4%CVE-2026-11068HIGHUse after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox viEPSS 0.4%CVE-2026-11074HIGHUse after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted EPSS 0.4%CVE-2026-6653HIGHlibxml2: Use after free in xmlParseInternalSubset via improper entity resolution handlingEPSS 0.4%CVE-2026-11147HIGHUse after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2023-2763HIGHUse-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023EPSS 0.4%CVE-2025-11719CRITICALUse-after-free caused by the native messaging web extension API on WindowsEPSS 0.4%CVE-2021-3760—A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, anEPSS 0.4%