Weaknesses of type CWE-416

5,143 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-20046HIGHUse after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentEPSS 0.2%CVE-2023-20937HIGHIn several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. This could lead to locaEPSS 0.2%CVE-2024-56561HIGHPCI: endpoint: Fix PCI domain ID release in pci_epc_destroy()EPSS 0.2%CVE-2025-0084HIGHIn multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over BluetoEPSS 0.2%CVE-2024-35843HIGHiommu/vt-d: Use device rbtree in iopf reporting pathEPSS 0.2%CVE-2025-54242HIGHPremiere Pro | Use After Free (CWE-416)EPSS 0.2%CVE-2023-42870HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app mEPSS 0.2%CVE-2026-28984MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadEPSS 0.2%CVE-2025-21671HIGHzram: fix potential UAF of zram tableEPSS 0.2%CVE-2022-48670HIGHpeci: cpu: Fix use-after-free in adev_release()EPSS 0.2%CVE-2026-32091HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-54281HIGHAdobe Framemaker | Use After Free (CWE-416)EPSS 0.2%CVE-2025-36940HIGHUse-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (EPSS 0.2%CVE-2025-4516MEDIUMUse-after-free in "unicode_escape" decoder with error handlerEPSS 0.2%CVE-2025-61802HIGHSubstance3D - Stager | Use After Free (CWE-416)EPSS 0.2%CVE-2026-103630—Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via EPSS 0.2%CVE-2025-21934HIGHrapidio: fix an API misues when rio_add_net() failsEPSS 0.2%CVE-2023-3159MEDIUMA use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker EPSS 0.2%CVE-2026-74973MEDIUMRace condition, use-after-free in the Graphics componentEPSS 0.2%CVE-2026-103623—Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandboxEPSS 0.2%