Weaknesses of type CWE-416

5,143 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-100805HIGHRace condition, use-after-free in the Audio/Video componentEPSS 0.2%CVE-2024-27530HIGHwasm3 139076a contains a Use-After-Free in ForEachModule.EPSS 0.2%CVE-2022-49842HIGHASoC: core: Fix use-after-free in snd_soc_exit()EPSS 0.2%CVE-2024-9126HIGHUse after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in speciEPSS 0.2%CVE-2026-12467HIGHUse after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to EPSS 0.2%CVE-2026-9932HIGHUse after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer proceEPSS 0.2%CVE-2026-12464HIGHUse after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potEPSS 0.2%CVE-2025-54229HIGHAdobe Framemaker | Use After Free (CWE-416)EPSS 0.2%CVE-2024-50261HIGHmacsec: Fix use-after-free while sending the offloading packetEPSS 0.2%CVE-2023-52576MEDIUMx86/mm, kexec, ima: Use memblock_free_late() from ima_free_kexec_buffer()EPSS 0.2%CVE-2024-53068HIGHfirmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier()EPSS 0.2%CVE-2023-1252HIGHA use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations simultaneously with thEPSS 0.2%CVE-2026-3779HIGHFoxit PDF Editor/Reader List Box Calculate Array Use-After-Free VulnerabilityEPSS 0.2%CVE-2024-56623HIGHscsi: qla2xxx: Fix use after free on unloadEPSS 0.2%CVE-2023-40140HIGHIn android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after freEPSS 0.2%CVE-2026-10003HIGHUse after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gesEPSS 0.2%CVE-2024-56759HIGHbtrfs: fix use-after-free when COWing tree bock and tracing is enabledEPSS 0.2%CVE-2022-50367HIGHfs: fix UAF/GPF bug in nilfs_mdt_destroyEPSS 0.2%CVE-2025-54258HIGHSubstance3D - Modeler | Use After Free (CWE-416)EPSS 0.2%CVE-2024-56541HIGHwifi: ath12k: fix use-after-free in ath12k_dp_cc_cleanup()EPSS 0.2%