Weaknesses of type CWE-416

5,143 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-21329HIGHAfter Effects | Use After Free (CWE-416)EPSS 0.2%CVE-2026-11188HIGHUse after free in USB in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape vEPSS 0.2%CVE-2026-11165CRITICALUse after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape vEPSS 0.2%CVE-2026-21221HIGHCapability Access Management Service (camsvc) Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2022-48674HIGHerofs: fix pcluster use-after-free on UP platformsEPSS 0.2%CVE-2026-21326HIGHAfter Effects | Use After Free (CWE-416)EPSS 0.2%CVE-2026-11082CRITICALRace in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.2%CVE-2024-32610MEDIUMHDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.EPSS 0.2%CVE-2026-11177HIGHUse after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI geEPSS 0.2%CVE-2021-47068HIGHnet/nfc: fix use-after-free llcp_sock_bind/connectEPSS 0.2%CVE-2024-50186HIGHnet: explicitly clear the sk pointer, when pf->create failsEPSS 0.2%CVE-2024-50051HIGHspi: mpc52xx: Add cancel_work_sync before module removeEPSS 0.2%CVE-2024-11155HIGHRockwell Automation Arena® Use After Free VulnerabilityEPSS 0.2%CVE-2022-49753HIGHdmaengine: Fix double increment of client_count in dma_chan_get()EPSS 0.2%CVE-2026-10639MEDIUMUse-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`EPSS 0.2%CVE-2025-21812HIGHax25: rcu protect dev->ax25_ptrEPSS 0.2%CVE-2025-21786HIGHworkqueue: Put the pwq after detaching the rescuer from the poolEPSS 0.2%CVE-2023-1476HIGHKpatch: mm/mremap.c: incomplete fix for cve-2022-41222EPSS 0.2%CVE-2024-57984HIGHi3c: dw: Fix use-after-free in dw_i3c_master driver due to race conditionEPSS 0.2%CVE-2025-21700HIGHnet: sched: Disallow replacing of child qdisc from one parent to anotherEPSS 0.2%