Weaknesses of type CWE-416

5,149 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-43478MEDIUMA use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOEPSS 0.2%CVE-2022-20514MEDIUMIn acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possiEPSS 0.2%CVE-2025-59734HIGHHeap-buffer-overflow write in FFmpeg SANM process_ftchEPSS 0.2%CVE-2026-11628MEDIUMUse after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physicaEPSS 0.2%CVE-2026-71226HIGHLibkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio pathEPSS 0.2%CVE-2022-20554MEDIUMIn removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of priEPSS 0.2%CVE-2026-50219MEDIUMlibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParseEPSS 0.2%CVE-2026-28529HIGHcryptodev-linux <= 1.14 get_userbuf Use After Free LPEEPSS 0.2%CVE-2024-54030MEDIUMCommunication_dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2026-10002HIGHUse after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a craEPSS 0.2%CVE-2023-20928HIGHIn binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilegEPSS 0.2%CVE-2026-45782HIGHCloud Hypervisor: Use-after-free in virtio-block Async I/O CompletionEPSS 0.2%CVE-2026-11692HIGHUse after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process EPSS 0.2%CVE-2026-11679HIGHUse after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2024-0147MEDIUMNVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been freed can lead to denialEPSS 0.2%CVE-2026-1979MEDIUMmruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after freeEPSS 0.2%CVE-2026-11700HIGHUse after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potEPSS 0.2%CVE-2022-42520MEDIUMIn ServiceInterface::HandleRequest of serviceinterface.cpp, there is a possible use after free. This could lead to local escalation of priviEPSS 0.2%CVE-2024-30378MEDIUMJunos OS: MX Series: bbe-smgd process crash upon execution of specific CLI commandsEPSS 0.2%CVE-2026-56412MEDIUMlibexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls frEPSS 0.2%