Weaknesses of type CWE-416

5,142 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-59189HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-51779HIGHbt_sock_recvmsg in net/bluetooth/af_bluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a bt_sock_ioctl race condiEPSS 0.3%CVE-2022-4095HIGHA use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c,EPSS 0.3%CVE-2023-6039MEDIUMKernel: use-after-free in drivers/net/usb/lan78xx.c in lan78xx_disconnectEPSS 0.3%CVE-2025-44906HIGHjhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.EPSS 0.3%CVE-2026-10890HIGHUse after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap EPSS 0.3%CVE-2024-53174HIGHSUNRPC: make sure cache entry active before cache_showEPSS 0.3%CVE-2026-88032HIGHApplication denial of service via cancellation race in reactive client-side encryption in MongoDB Java DriverEPSS 0.3%CVE-2024-50257HIGHnetfilter: Fix use-after-free in get_info()EPSS 0.3%CVE-2022-41848MEDIUMdrivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proxEPSS 0.3%CVE-2026-50458HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50689HIGHWindows Clipboard Server Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-88097HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50427HIGHContent Delivery Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50677HIGHWindows Media Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-26181HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-54125HIGHWindows Runtime Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-32153HIGHWindows Speech Runtime Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-49568MEDIUMIllustrator | Use After Free (CWE-416)EPSS 0.3%CVE-2026-50385HIGHWindows Runtime Elevation of Privilege VulnerabilityEPSS 0.3%