Weaknesses of type CWE-416

5,184 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-57438LOWNokogiri: Possible Use-After-Free in XInclude ProcessingEPSS 0.1%CVE-2024-23365HIGHUse After Free in SCE-MinkEPSS 0.1%CVE-2026-20531HIGHIn apu, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege with no additional exeEPSS 0.1%CVE-2022-20552MEDIUMIn btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to a use after free. This could lead to locEPSS 0.1%CVE-2026-11623LOWtmux image.c image_free use after freeEPSS 0.1%CVE-2026-47590HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by EPSS 0.1%CVE-2026-47588HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free condition by issuing a EPSS 0.1%CVE-2026-47589HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by EPSS 0.1%CVE-2022-20158MEDIUMIn bdi_put and bdi_unregister of backing-dev.c, there is a possible memory corruption due to a use after free. This could lead to local escaEPSS 0.1%CVE-2026-47594HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by EPSS 0.1%CVE-2026-47587HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit oEPSS 0.1%CVE-2022-33245MEDIUMUse after free in WLANEPSS 0.1%CVE-2022-33225MEDIUMUse after free in Trusted Application EnvironmentEPSS 0.1%CVE-2023-28577MEDIUMMultiple Dmabuf Kernel Address UAF VulnerabilityEPSS 0.1%CVE-2026-4737HIGHUse-After-Free Vulnerability in No-Chicken/Echo-MateEPSS 0.1%CVE-2022-42754MEDIUMIn npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2022-25723HIGHMemory corruption in multimedia due to use after free during callback registration failure in Snapdragon MobileEPSS 0.1%CVE-2022-25666MEDIUMMemory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon Compute, EPSS 0.1%CVE-2025-0031MEDIUMA use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a diffeEPSS 0.1%CVE-2023-33108HIGHUse After Free in GraphicsEPSS 0.1%