Weaknesses of type CWE-416

5,138 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2022-49359HIGHdrm/panfrost: Job should reference MMU not file_privEPSS 0.3%CVE-2021-33641HIGHWhen processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memoryEPSS 0.3%CVE-2023-34970MEDIUMMali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsEPSS 0.3%CVE-2024-50269HIGHusb: musb: sunxi: Fix accessing an released usb phyEPSS 0.3%CVE-2022-49390HIGHmacsec: fix UAF bug for real_devEPSS 0.3%CVE-2023-33200MEDIUMMali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsEPSS 0.3%CVE-2026-11629HIGHUse after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.3%CVE-2023-23586MEDIUMUse after free in io_uring in the Linux KernelEPSS 0.3%CVE-2023-32269MEDIUMAn issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because accept is also allowEPSS 0.3%CVE-2026-102324HIGHUse after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2022-49524HIGHmedia: pci: cx23885: Fix the error handling in cx23885_initdev()EPSS 0.3%CVE-2024-56538HIGHdrm: zynqmp_kms: Unplug DRM device before removalEPSS 0.3%CVE-2024-1848HIGHMultiple vulnerabilities exist in file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024EPSS 0.3%CVE-2026-85197HIGHLibsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body uploadEPSS 0.3%CVE-2024-26852HIGHnet/ipv6: avoid possible UAF in ip6_route_mpath_notify()EPSS 0.3%CVE-2026-56113MEDIUMdhcpcd Heap Use-After-Free in dhcp6_deprecateaddrs via DHCPv6 RENEWEPSS 0.3%CVE-2025-11979MEDIUMUse-after-free in the MongoDB server query planner may lead to crash or undefined behaviorEPSS 0.3%CVE-2023-4611HIGHUse after free race between mbind() and vma-locked page faultEPSS 0.3%CVE-2026-9901HIGHUse after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execuEPSS 0.3%CVE-2026-13830HIGHUse after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via maliciEPSS 0.3%