Weaknesses of type CWE-416

5,143 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-53143HIGHfsnotify: Fix ordering of iput() and watched_objects decrementEPSS 0.2%CVE-2026-33021HIGHlibsixel: Use-after-free in sixel_encoder_encode_bytes()EPSS 0.2%CVE-2026-21287HIGHSubstance3D - Stager | Use After Free (CWE-416)EPSS 0.2%CVE-2024-14028MEDIUMMultiple implicit reads in parallel can result in a crash or denial of serviceEPSS 0.2%CVE-2023-3397HIGHKernel: slab-use-after-free write in txend due to race conditionEPSS 0.2%CVE-2025-21652HIGHipvlan: Fix use-after-free in ipvlan_get_iflink().EPSS 0.2%CVE-2024-8422HIGHCWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & inteEPSS 0.2%CVE-2024-32929HIGHIn gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege EPSS 0.2%CVE-2023-53322HIGHscsi: qla2xxx: Wait for io return on terminate rportEPSS 0.2%CVE-2024-57887HIGHdrm: adv7511: Fix use-after-free in adv7533_attach_dsi()EPSS 0.2%CVE-2025-54335MEDIUMAn issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the XclipsEPSS 0.2%CVE-2025-46710MEDIUMPossible kernel exceptions caused by reading and writing kernel heap data after free.EPSS 0.2%CVE-2024-56765HIGHpowerpc/pseries/vas: Add close() callback in vas_vm_ops structEPSS 0.2%CVE-2023-1195MEDIUMA use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgetEPSS 0.2%CVE-2024-50084HIGHnet: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()EPSS 0.2%CVE-2025-6555MEDIUMUse after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.2%CVE-2026-102760HIGHWhen NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. BEPSS 0.2%CVE-2025-33220HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the mEPSS 0.2%CVE-2026-2660MEDIUMFascinatedBox lily lily_symtab.c shorthash_for_name use after freeEPSS 0.2%CVE-2025-22068HIGHublk: make sure ubq->canceling is set when queue is frozenEPSS 0.2%