Weaknesses of type CWE-416

5,184 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-17699HIGHUse after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicEPSS 0.1%CVE-2026-4752MEDIUMUse After Free in No-Chicken Echo-MateEPSS 0.1%CVE-2025-14569MEDIUMggml-org whisper.cpp common-whisper.cpp read_audio_data use after freeEPSS 0.1%CVE-2022-22077HIGHMemory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon MobileEPSS 0.1%CVE-2023-20920HIGHIn queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of priviEPSS 0.1%CVE-2026-71968HIGHOP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENTEPSS 0.1%CVE-2026-91791HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.1%CVE-2026-17932MEDIUMUse after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive iEPSS 0.1%CVE-2025-5991LOWUse after free in QHttp2ProtocolHandlerEPSS 0.1%CVE-2026-57842HIGHNetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlenEPSS 0.1%CVE-2026-56117MEDIUMdhcpcd Heap Use-After-Free via Control Socket HandlingEPSS 0.1%CVE-2026-13713MEDIUMYAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stackEPSS 0.1%CVE-2026-91799HIGHFoxit Editor/Reader Array resetForm Use-After-Free VulnerabilityEPSS 0.1%CVE-2026-87514HIGHUse after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via aEPSS 0.1%CVE-2024-45553HIGHUse After Free in DSP ServicesEPSS 0.1%CVE-2026-47560HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a use-after-freEPSS 0.1%CVE-2026-47516HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successfEPSS 0.1%CVE-2026-79245HIGHUse after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer process to execute arEPSS 0.1%CVE-2026-47551HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause a use-after-free.EPSS 0.1%CVE-2024-33059MEDIUMUse After Free in Computer VisionEPSS 0.1%