Weaknesses of type CWE-416

5,149 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-53373HIGHcrypto: seqiv - Handle EBUSY correctlyEPSS 0.2%CVE-2026-6654MEDIUMUse-After-Free and Double-Free in IntoIter::drop when element drop panicsEPSS 0.2%CVE-2025-11797HIGHDWG File Parsing Use-After-Free VulnerabilityEPSS 0.2%CVE-2026-15194MEDIUMOpen5GS AMF context.c amf_context_final use after freeEPSS 0.2%CVE-2025-64468HIGHUse-after-Free in sentry!sentry_span_set_data() in NI LabVIEWEPSS 0.2%CVE-2023-53316HIGHdrm/msm/dp: Free resources after unregistering themEPSS 0.2%CVE-2022-50422HIGHscsi: libsas: Fix use-after-free bug in smp_execute_task_sg()EPSS 0.2%CVE-2022-50408HIGHwifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit()EPSS 0.2%CVE-2024-38402HIGHUse After Free in DSP ServicesEPSS 0.2%CVE-2026-5940HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.2%CVE-2023-53307HIGHrbd: avoid use-after-free in do_rbd_add() when rbd_dev_create() failsEPSS 0.2%CVE-2023-53311HIGHnilfs2: fix use-after-free of nilfs_root in dirtying inodes via iputEPSS 0.2%CVE-2026-6424MEDIUMUse-after-free vulnerability in ESET security products for LinuxEPSS 0.2%CVE-2022-50417HIGHdrm/panfrost: Fix GEM handle creation ref-countingEPSS 0.2%CVE-2026-18785MEDIUMo6 open62541 client_types_custom.c UA_Client_getRemoteDataTypes use after freeEPSS 0.2%CVE-2023-53282HIGHscsi: lpfc: Fix use-after-free KFENCE violation during sysfs firmware writeEPSS 0.2%CVE-2026-84567MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. AnEPSS 0.2%CVE-2025-65955MEDIUMImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing familyEPSS 0.2%CVE-2026-3979MEDIUMquickjs-ng quickjs quickjs.c js_iterator_concat_return use after freeEPSS 0.2%CVE-2026-21486HIGHUse After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write in iccDEVEPSS 0.2%