Weaknesses of type CWE-416

5,143 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-26957HIGHs390/zcrypt: fix reference counting on zcrypt card objectsEPSS 0.2%CVE-2023-52999HIGHnet: fix UaF in netns ops registration error pathEPSS 0.2%CVE-2024-56605HIGHBluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()EPSS 0.2%CVE-2023-4244HIGHUse-after-free in Linux kernel's netfilter: nf_tables componentEPSS 0.2%CVE-2024-26598HIGHKVM: arm64: vgic-its: Avoid potential UAF in LPI translation cacheEPSS 0.2%CVE-2026-100761HIGHPrivilege escalation due to use-after-free in the Graphics: WebGPU componentEPSS 0.2%CVE-2024-53170HIGHblock: fix uaf for flush rq while iterating tagsEPSS 0.2%CVE-2022-3424HIGHA use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the EPSS 0.2%CVE-2024-58013HIGHBluetooth: MGMT: Fix slab-use-after-free Read in mgmt_remove_adv_monitor_syncEPSS 0.2%CVE-2026-76875MEDIUMPyPy pyexpat ExternalEntityParserCreate Use-After-FreeEPSS 0.2%CVE-2025-9386MEDIUMappneta tcpreplay tcprewrite get.c get_l2len_protocol use after freeEPSS 0.2%CVE-2023-52926HIGHio_uring/rw: split io_read() into a helperEPSS 0.2%CVE-2024-53208HIGHBluetooth: MGMT: Fix slab-use-after-free Read in set_powered_syncEPSS 0.2%CVE-2024-56551HIGHdrm/amdgpu: fix usage slab after freeEPSS 0.2%CVE-2024-50226HIGHcxl/port: Fix use-after-free, permit out-of-order decoder shutdownEPSS 0.2%CVE-2024-42326MEDIUMUse after free vulnerability in browser.cEPSS 0.2%CVE-2026-11250CRITICALInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2023-39549HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 2). The affected application contains a use-after-freEPSS 0.2%CVE-2023-46691HIGHUse after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation oEPSS 0.2%CVE-2024-56603HIGHnet: af_can: do not leave a dangling sk pointer in can_create()EPSS 0.2%