Weaknesses of type CWE-416

5,110 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-19154HIGHUse after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2026-8390HIGHUse-after-free in the JavaScript: WebAssembly componentEPSS 0.3%CVE-2025-55686HIGHWindows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-22165HIGHGPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/write of RMJob::apsCCBsEPSS 0.3%CVE-2025-55331HIGHWindows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-50174HIGHWindows Device Association Broker Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-55689HIGHWindows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-55685HIGHWindows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-59202HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-3922HIGHUse after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.3%CVE-2026-13792CRITICALUse after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape EPSS 0.3%CVE-2026-3923HIGHUse after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a craEPSS 0.3%CVE-2026-14043CRITICALUse after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process toEPSS 0.3%CVE-2026-3918HIGHUse after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.3%CVE-2026-17804CRITICALUse after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.3%CVE-2026-17670CRITICALUse after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.3%CVE-2024-25443HIGHAn issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via pEPSS 0.3%CVE-2026-14390CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.3%CVE-2026-9886CRITICALUse after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape viaEPSS 0.3%CVE-2026-14025HIGHUse after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific EPSS 0.3%