Weaknesses of type CWE-416

5,143 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-84783HIGHUse-After-Free in X.509 Extension Cache Under Concurrent UseEPSS 0.2%CVE-2022-49127HIGHref_tracker: implement use-after-free detectionEPSS 0.2%CVE-2026-14425CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2024-0775MEDIUMKernel: use-after-free while changing the mount option in __ext4_remount leadingEPSS 0.2%CVE-2023-53305HIGHBluetooth: L2CAP: Fix use-after-freeEPSS 0.2%CVE-2026-9899HIGHUse after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potenEPSS 0.2%CVE-2026-12012HIGHUse after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploEPSS 0.2%CVE-2026-9904HIGHUse after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a craEPSS 0.2%CVE-2024-56678HIGHpowerpc/mm/fault: Fix kfence page fault reportingEPSS 0.2%CVE-2024-49570HIGHdrm/xe/tracing: Fix a potential TP_printk UAFEPSS 0.2%CVE-2026-11306HIGHUse after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.2%CVE-2026-12020HIGHUse after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption EPSS 0.2%CVE-2023-52566MEDIUMnilfs2: fix potential use after free in nilfs_gccache_submit_read_data()EPSS 0.2%CVE-2024-56604HIGHBluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc()EPSS 0.2%CVE-2022-28192MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn mEPSS 0.2%CVE-2024-53182HIGHRevert "block, bfq: merge bfq_release_process_ref() into bfq_put_cooperator()"EPSS 0.2%CVE-2024-58083HIGHKVM: Explicitly verify target vCPU is online in kvm_get_vcpu()EPSS 0.2%CVE-2026-11670HIGHUse after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crEPSS 0.2%CVE-2021-47670HIGHcan: peak_usb: fix use after free bugsEPSS 0.2%CVE-2026-6362MEDIUMUse after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory acceEPSS 0.2%