Weaknesses of type CWE-416

5,138 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-26991HIGHSWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c.EPSS 0.3%CVE-2026-91710CRITICALUse after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sanEPSS 0.3%CVE-2026-91722HIGHUse after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the EPSS 0.3%CVE-2022-45885HIGHAn issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-aEPSS 0.3%CVE-2024-56653HIGHBluetooth: btmtk: avoid UAF in btmtk_process_coredumpEPSS 0.3%CVE-2026-102309CRITICALUse after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandboxEPSS 0.3%CVE-2026-102308CRITICALUse after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitraryEPSS 0.3%CVE-2021-4083—A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call EPSS 0.3%CVE-2026-102316CRITICALUse after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitraryEPSS 0.3%CVE-2021-40790MEDIUMAdobe Premiere Pro MOV File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-102304CRITICALUse after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox EPSS 0.3%CVE-2023-22424HIGHUse-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlEPSS 0.3%CVE-2022-1419—The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_gem_object *(created iEPSS 0.3%CVE-2026-56000CRITICALxorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()EPSS 0.3%CVE-2024-3171HIGHUse after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who convinced a user to engage in specificEPSS 0.3%CVE-2026-10636LOWUse-after-free in Zephyr IPv4 IGMP send path (`igmp_send`)EPSS 0.3%CVE-2024-26898HIGHaoe: fix the potential use-after-free problem in aoecmd_cfg_pktsEPSS 0.3%CVE-2026-15924MEDIUMUse-after-free / double-free from unsynchronized concurrent access to the TLS client session cache in Zephyr socketsEPSS 0.3%CVE-2021-39216MEDIUMUse after free passing `externref`s to Wasm in WasmtimeEPSS 0.3%CVE-2026-20918HIGHWindows Management Services Elevation of Privilege VulnerabilityEPSS 0.3%