Weaknesses of type CWE-416

5,138 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-29699MEDIUMNetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.EPSS 0.3%CVE-2026-50459HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-17920HIGHUse after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to exEPSS 0.3%CVE-2026-13774HIGHUse after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extensiEPSS 0.3%CVE-2024-8816LOWPDF-XChange Editor U3D File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.3%CVE-2025-47106MEDIUMInDesign Desktop | Use After Free (CWE-416)EPSS 0.3%CVE-2024-27052HIGHwifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_workEPSS 0.3%CVE-2026-12293CRITICALUse-after-free in the Graphics: WebGPU componentEPSS 0.3%CVE-2026-11368HIGHUse-after-free in Bluetooth host ATT TX completion on disconnect mid-transferEPSS 0.3%CVE-2024-22914MEDIUMA heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620. It allows an attacker to cause denial of serviEPSS 0.3%CVE-2026-100804CRITICALSandbox escape due to use-after-free in the Preferences: Backend componentEPSS 0.3%CVE-2024-9729HIGHTrimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-10932HIGHUse after free in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption viaEPSS 0.3%CVE-2025-31197MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS SonoEPSS 0.3%CVE-2026-12441HIGHUse after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruptEPSS 0.3%CVE-2026-100768HIGHUse-after-free in the Graphics: WebGPU componentEPSS 0.3%CVE-2021-3543—A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave fiEPSS 0.3%CVE-2026-11042HIGHUse after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestEPSS 0.3%CVE-2026-92021HIGHUse-after-free in the JavaScript Engine: JIT componentEPSS 0.3%CVE-2024-9748HIGHTungsten Automation Power PDF XPS File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%