Weaknesses of type CWE-416

5,143 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-21786HIGHworkqueue: Put the pwq after detaching the rescuer from the poolEPSS 0.2%CVE-2024-57984HIGHi3c: dw: Fix use-after-free in dw_i3c_master driver due to race conditionEPSS 0.2%CVE-2022-49755HIGHusb: gadget: f_fs: Prevent race during ffs_ep0_queue_waitEPSS 0.2%CVE-2024-53232HIGHiommu/s390: Implement blocking domainEPSS 0.2%CVE-2026-56373MEDIUMImageMagick - Use-After-Free Write in PDB DecoderEPSS 0.2%CVE-2025-21731HIGHnbd: don't allow reconnect after disconnectEPSS 0.2%CVE-2023-52921HIGHdrm/amdgpu: fix possible UAF in amdgpu_cs_pass1()EPSS 0.2%CVE-2023-4133MEDIUMKernel: cxgb4: use-after-free in ch_flower_stats_cb()EPSS 0.2%CVE-2024-50274HIGHidpf: avoid vport access in idpf_get_link_ksettingsEPSS 0.2%CVE-2026-32724MEDIUMPX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race ConditionEPSS 0.2%CVE-2023-1855MEDIUMA use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hEPSS 0.2%CVE-2021-46973HIGHnet: qrtr: Avoid potential use after free in MHI sendEPSS 0.2%CVE-2025-6119MEDIUMOpen Asset Import Library Assimp BVHLoader.cpp ReadNodeChannels use after freeEPSS 0.2%CVE-2025-61817HIGHInCopy | Use After Free (CWE-416)EPSS 0.2%CVE-2025-61818HIGHInCopy | Use After Free (CWE-416)EPSS 0.2%CVE-2026-22040MEDIUMNanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker CrashEPSS 0.2%CVE-2025-61834HIGHSubstance3D - Stager | Use After Free (CWE-416)EPSS 0.2%CVE-2026-11642HIGHUse after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to poEPSS 0.2%CVE-2026-87657LOWUse after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memoEPSS 0.2%CVE-2025-61801HIGHDimension | Use After Free (CWE-416)EPSS 0.2%