Weaknesses of type CWE-416

5,149 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-13126HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-57249HIGHFoxit PDF Editor/Reader Annotation Use-After-Free VulnerabilityEPSS 0.2%CVE-2026-13127HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-57245HIGHFoxit PDF Editor/Reader Signature Hyperlink Use-After-Free VulnerabilityEPSS 0.2%CVE-2025-0304HIGHLiteos_a has an use after free vulnerabilityEPSS 0.2%CVE-2026-57237HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-57242HIGHFoxit PDF Editor/Reader Page Use-After-Free VulnerabilityEPSS 0.2%CVE-2025-20626LOWArkcompiler Ets Runtime has an UAF vulnerabilityEPSS 0.2%CVE-2026-0001MEDIUMMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2026-57589HIGHsys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-afEPSS 0.2%CVE-2026-7349HIGHUse after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code iEPSS 0.2%CVE-2023-6363MEDIUMMali GPU Kernel Driver allows improper GPU processing operationsEPSS 0.2%CVE-2025-23409LOWCommunication Dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2026-11656HIGHUse after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extEPSS 0.2%CVE-2025-23414LOWArkcompiler Ets Runtime has an UAF vulnerabilityEPSS 0.2%CVE-2025-20091LOWCommunication Dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2025-24301LOWArkcompiler Ets Runtime has an UAF vulnerabilityEPSS 0.2%CVE-2026-90827MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2026-43684HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27,EPSS 0.2%CVE-2026-90578MEDIUMGPAC MP4Box list.c gf_list_count use after freeEPSS 0.2%