Weaknesses of type CWE-416

5,142 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-6519HIGHQemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerabilityEPSS 0.2%CVE-2025-20006HIGHUse after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentEPSS 0.2%CVE-2025-59220HIGHWindows Bluetooth Service Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2023-52447HIGHbpf: Defer the free of inner map when necessaryEPSS 0.2%CVE-2025-59216HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2023-2162MEDIUMA use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux KerneEPSS 0.2%CVE-2022-49694HIGHblock: disable the elevator int del_gendiskEPSS 0.2%CVE-2022-49047HIGHep93xx: clock: Fix UAF in ep93xx_clk_register_gate()EPSS 0.2%CVE-2022-49669HIGHmptcp: fix race on unaccepted mptcp socketsEPSS 0.2%CVE-2025-6856MEDIUMHDF5 H5FL.c H5FL__reg_gc_list use after freeEPSS 0.2%CVE-2026-92049HIGHUse-after-free in the Widget: Win32 componentEPSS 0.2%CVE-2026-92060HIGHUse-after-free in the Internationalization componentEPSS 0.2%CVE-2026-100815HIGHUse-after-free in the CSS Parsing and Computation componentEPSS 0.2%CVE-2026-92056HIGHUse-after-free in the Graphics: Text componentEPSS 0.2%CVE-2023-3472HIGHUse after free vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.EPSS 0.2%CVE-2026-14390CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2026-92067HIGHUse-after-free in the Widget: Gtk componentEPSS 0.2%CVE-2026-100825HIGHUse-after-free in the JavaScript Engine: JIT componentEPSS 0.2%CVE-2026-92058HIGHUse-after-free in the Graphics componentEPSS 0.2%CVE-2022-46282HIGHUse after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specEPSS 0.2%