Weaknesses of type CWE-416

5,149 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-90825MEDIUMGPAC MP4Box base_scenegraph.c gf_node_unregister use after freeEPSS 0.2%CVE-2025-22411HIGHIn process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. This could lead to remEPSS 0.2%CVE-2023-53235HIGHdrm/tests: helpers: Avoid a driver uafEPSS 0.2%CVE-2026-92474MEDIUMGPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after freeEPSS 0.2%CVE-2024-39831MEDIUMAccessTokenManager has an use after free vulnerabilityEPSS 0.2%CVE-2026-57076HIGHYAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchorEPSS 0.2%CVE-2026-43684HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27,EPSS 0.2%CVE-2026-49422HIGHUse-after-free in TCP RACK stack option handlerEPSS 0.2%CVE-2026-13595MEDIUMUtil-linux: util-linux: heap use-after-free in libblkid nested partition probingEPSS 0.2%CVE-2026-90578MEDIUMGPAC MP4Box list.c gf_list_count use after freeEPSS 0.2%CVE-2026-58083HIGHUse-after-free in kqueue copy-on-forkEPSS 0.2%CVE-2026-92472MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2026-90827MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2024-47898HIGHGPU DDK - PVRSRVDeviceSyncOpen use-after-free conditionEPSS 0.2%CVE-2026-34196HIGHGPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMemEPSS 0.2%CVE-2026-24200HIGHNVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. AEPSS 0.2%CVE-2025-58411HIGHGPU DDK - Reservation::psMappedPMR can change while used by a freelist -> UAFEPSS 0.2%CVE-2026-2656LOWChaiScript type_info.hpp bare_equal use after freeEPSS 0.2%CVE-2024-12837HIGHGPU DDK - Exploitable kernel double free on apsFenceSyncCheckpoints allocated with arbitrary sizeEPSS 0.2%CVE-2022-50384HIGHstaging: vme_user: Fix possible UAF in tsi148_dma_list_addEPSS 0.2%