Weaknesses of type CWE-416

5,143 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-3317HIGHA use-after-free flaw was found in mt7921_check_offload_capability in drivers/net/wireless/mediatek/mt76/mt7921/init.c in wifi mt76/mt7921 sEPSS 0.2%CVE-2023-39549HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 2). The affected application contains a use-after-freEPSS 0.2%CVE-2024-53103HIGHhv_sock: Initializing vsk->trans to NULL to prevent a dangling pointerEPSS 0.2%CVE-2023-46691HIGHUse after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation oEPSS 0.2%CVE-2024-38588HIGHftrace: Fix possible use-after-free issue in ftrace_location()EPSS 0.2%CVE-2024-56582HIGHbtrfs: fix use-after-free in btrfs_encoded_read_endio()EPSS 0.2%CVE-2023-52931HIGHdrm/i915: Avoid potential vm use-after-freeEPSS 0.2%CVE-2024-53194HIGHPCI: Fix use-after-free of slot->bus on hot removeEPSS 0.2%CVE-2023-24581HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (AEPSS 0.2%CVE-2025-66585HIGHUse After Free vulnerability in AzeoTech DAQFactoryEPSS 0.2%CVE-2025-48798HIGHGimp: multiple use after free in xcf parserEPSS 0.2%CVE-2025-26603MEDIUMheap-use-after-free in function str_to_reg in vim/vimEPSS 0.2%CVE-2023-25006HIGHA malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which could result in codEPSS 0.2%CVE-2026-10663MEDIUMUse-after-free / double-free of the root USB device in the experimental USB host stackEPSS 0.2%CVE-2024-50121HIGHnfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_netEPSS 0.2%CVE-2026-11303HIGHUse after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.2%CVE-2025-23280HIGHNVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerEPSS 0.2%CVE-2024-56581HIGHbtrfs: ref-verify: fix use-after-free after invalid ref actionEPSS 0.2%CVE-2025-21726HIGHpadata: avoid UAF for reorder_workEPSS 0.2%CVE-2021-47456HIGHcan: peak_pci: peak_pci_remove(): fix UAFEPSS 0.2%