Weaknesses of type CWE-416

5,184 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-23696HIGHIn RGXCreateZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalatiEPSS 0.1%CVE-2024-23697HIGHIn RGXCreateHWRTData_aux of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalaEPSS 0.1%CVE-2026-7925HIGHUse after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalEPSS 0.1%CVE-2024-33034HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2025-27723MEDIUMUse after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Kernel may allow a denEPSS 0.1%CVE-2024-38419HIGHUse After Free in Automotive GPUEPSS 0.1%CVE-2024-38424HIGHUse After Free in GPSEPSS 0.1%CVE-2024-38421HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2025-47358HIGHUse After Free in Secure ProcessorEPSS 0.1%CVE-2024-38415HIGHUse After Free in Computer VisionEPSS 0.1%CVE-2025-47359HIGHUse After Free in Secure ProcessorEPSS 0.1%CVE-2024-45571HIGHUse After Free in WLAN Host CommunicationEPSS 0.1%CVE-2026-58751MEDIUMIn multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalaEPSS 0.1%CVE-2024-38412MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2024-33053MEDIUMUse After Free in VideoEPSS 0.1%CVE-2024-33033MEDIUMUse After Free in ComputerVisionEPSS 0.1%CVE-2024-33029MEDIUMUse After Free in DSP ServicesEPSS 0.1%CVE-2026-20411HIGHIn cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious aEPSS 0.1%CVE-2023-43544MEDIUMUse After Free in AudioEPSS 0.1%CVE-2024-33055MEDIUMUse After Free in Computer VisionEPSS 0.1%