Weaknesses of type CWE-416

5,149 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-23380HIGHUse After Free in GraphicsEPSS 0.2%CVE-2026-34757MEDIUMLIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosureEPSS 0.2%CVE-2021-37690MEDIUMUse after free and segfault in shape inference functions in TensorFlowEPSS 0.2%CVE-2026-73282MEDIUMIn ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.EPSS 0.2%CVE-2022-50411HIGHACPICA: Fix error code path in acpi_ds_call_control_method()EPSS 0.2%CVE-2025-23281HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race conditioEPSS 0.2%CVE-2025-39855HIGHice: fix NULL access of tx->in_use in ice_ptp_ts_irqEPSS 0.2%CVE-2026-5729HIGHMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2026-7476HIGHMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2026-5939MEDIUMUAF in Foxit PDF Editor/Reader via XFA calculate eventEPSS 0.2%CVE-2026-41158HIGHGPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrinkEPSS 0.2%CVE-2026-49743HIGHGPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closedEPSS 0.2%CVE-2026-7477HIGHMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2026-45200HIGHGPU DDK - Double free in _FreeOSPages due to incorrect allocation flag set by _EncodeAllocationFlagsEPSS 0.2%CVE-2026-9034HIGHMali GPU Userspace Driver allows access to already freed memoryEPSS 0.2%CVE-2025-60466MEDIUMA use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackersEPSS 0.2%CVE-2025-6636HIGHPRT File Parsing Use-After-Free VulnerabilityEPSS 0.2%CVE-2026-41156HIGHGPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding referenceEPSS 0.2%CVE-2026-34192HIGHGPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entriesEPSS 0.2%CVE-2026-14366MEDIUMSiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pktEPSS 0.2%