Weaknesses of type CWE-416

5,184 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-43547HIGHUse After Free in Automotive MultimediaEPSS 0.1%CVE-2026-20515MEDIUMIn gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privilegEPSS 0.1%CVE-2023-43514HIGHUse After Free in DSP ServicesEPSS 0.1%CVE-2024-45544MEDIUMUse After Free in Data Network Stack & ConnectivityEPSS 0.1%CVE-2024-23370MEDIUMUse After Free in Automotive MultimediaEPSS 0.1%CVE-2026-57554HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2018-11816HIGHUse After Free in VideoEPSS 0.1%CVE-2024-23376MEDIUMUse After Free in ComputerVisionEPSS 0.1%CVE-2026-57555HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2023-33118HIGHUse After Free in Automotive AudioEPSS 0.1%CVE-2026-25291HIGHUse After Free in GraphicsEPSS 0.1%CVE-2024-45540MEDIUMUse After Free in HLOSEPSS 0.1%CVE-2023-33117HIGHUse After Free in AudioEPSS 0.1%CVE-2023-33120HIGHUse After Free in AudioEPSS 0.1%CVE-2026-57559HIGHUse After Free in DSP_ServicesEPSS 0.1%CVE-2026-57537HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2023-43521MEDIUMUse After Free in HLOSEPSS 0.1%CVE-2026-11891MEDIUMMali GPU Userspace Driver allows access to already freed memoryEPSS 0.1%CVE-2026-20537MEDIUMIn aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor EPSS 0.1%CVE-2026-13827HIGHUse after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a maliEPSS 0.1%