Weaknesses of type CWE-416

5,138 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2022-49179HIGHblock, bfq: don't move oom_bfqqEPSS 0.3%CVE-2026-100811CRITICALSandbox escape due to use-after-free in the DOM: Core & HTML componentEPSS 0.3%CVE-2026-3919HIGHUse after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extensiEPSS 0.3%CVE-2026-14044CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.3%CVE-2022-49176HIGHbfq: fix use-after-free in bfq_dispatch_requestEPSS 0.3%CVE-2026-21237HIGHWindows Subsystem for Linux Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-52983HIGHblock, bfq: fix uaf for bfqq in bic_set_bfqq()EPSS 0.3%CVE-2023-4755MEDIUMUse After Free in gpac/gpacEPSS 0.3%CVE-2026-69890HIGHWindows Virtual Trusted Platform Module Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-49626HIGHsfc: fix use after free when disabling sriovEPSS 0.3%CVE-2024-50217HIGHbtrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()EPSS 0.3%CVE-2022-49685HIGHiio: trigger: sysfs: fix use-after-free on removeEPSS 0.3%CVE-2022-32903HIGHA use after free issue was addressed with improved memory management. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able EPSS 0.3%CVE-2026-11639HIGHUse after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafEPSS 0.3%CVE-2022-41858HIGHA flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in EPSS 0.3%CVE-2026-15772HIGHUse after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer processEPSS 0.3%CVE-2022-49236HIGHbpf: Fix UAF due to race between btf_try_get_module and load_moduleEPSS 0.3%CVE-2026-10915HIGHUse after free in Core in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to EPSS 0.3%CVE-2022-49287HIGHtpm: fix reference counting for struct tpm_chipEPSS 0.3%CVE-2022-49711HIGHbus: fsl-mc-bus: fix KASAN use-after-free in fsl_mc_bus_remove()EPSS 0.3%