Weaknesses of type CWE-416

5,149 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-47899HIGHGPU DDK - PVRSRVDeviceServicesOpen use-after-free conditionEPSS 0.2%CVE-2026-47331HIGHUse-after-free in Ubuntu Linux AppArmor notification handlingEPSS 0.2%CVE-2026-2655LOWChaiScript chaiscript_defines.hpp operator use after freeEPSS 0.2%CVE-2024-47891HIGHGPU DDK - Exploitable double free on PTL_STREAM_DESC object in the kernel function TLServerCloseStreamKM due to a race conditionEPSS 0.2%CVE-2025-0015HIGHMali GPU Kernel Driver allows improper GPU processing operationsEPSS 0.2%CVE-2026-20473MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.2%CVE-2025-6349MEDIUMMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2024-33060HIGHUse After Free in DSP ServiceEPSS 0.2%CVE-2024-3655HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2025-23402HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%CVE-2026-95298HIGHUse after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside theEPSS 0.2%CVE-2025-47342HIGHUse After Free in BT ControllerEPSS 0.2%CVE-2026-7338HIGHUse after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heapEPSS 0.2%CVE-2026-12366HIGHUse-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposalEPSS 0.2%CVE-2022-22058HIGHMemory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnEPSS 0.2%CVE-2023-53219HIGHmedia: netup_unidvb: fix use-after-free at del_timer()EPSS 0.2%CVE-2026-10635MEDIUMDangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-initEPSS 0.2%CVE-2022-20502MEDIUMIn GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local informatioEPSS 0.2%CVE-2025-0835HIGHGPU DDK - _WrapExtMemReleasePages called twice if _FlushUMVirtualRange failsEPSS 0.2%CVE-2026-34757MEDIUMLIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosureEPSS 0.2%