Weaknesses of type CWE-416

5,149 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-11249MEDIUMUse after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtaEPSS 0.2%CVE-2026-10014HIGHUse after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2025-7042HIGHUse After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2026-10000HIGHUse after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer pEPSS 0.2%CVE-2023-6143HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2025-6971HIGHUse After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2026-42958HIGHUse After Free in Labcenter ProteusEPSS 0.2%CVE-2026-23401HIGHKVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTEEPSS 0.2%CVE-2026-40311MEDIUMImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing valuesEPSS 0.2%CVE-2024-4607HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2025-60471MEDIUMA use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 alEPSS 0.2%CVE-2026-16147MEDIUMit82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruptionEPSS 0.2%CVE-2026-47586MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel module where an attacker could cause a use-after-freeEPSS 0.2%CVE-2022-20540HIGHIn SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to locaEPSS 0.2%CVE-2024-28951MEDIUMArkcompiler runtime has a use after free vulnerabilityEPSS 0.2%CVE-2026-39316MEDIUMCUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointerEPSS 0.2%CVE-2026-10012HIGHUse after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.2%CVE-2023-28469MEDIUMAn issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access EPSS 0.2%CVE-2026-28529HIGHcryptodev-linux <= 1.14 get_userbuf Use After Free LPEEPSS 0.2%CVE-2025-43478MEDIUMA use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOEPSS 0.2%