Weaknesses of type CWE-416

5,184 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2017-18153MEDIUMUse After Free in WLANEPSS 0.1%CVE-2024-38411MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2025-22404HIGHIn avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local EPSS 0.1%CVE-2025-48521MEDIUMImproper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) conditEPSS 0.1%CVE-2025-22410HIGHIn multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of priEPSS 0.1%CVE-2025-22406HIGHIn bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to lEPSS 0.1%CVE-2025-22405HIGHIn multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of priEPSS 0.1%CVE-2025-47322HIGHUse After Free in Automotive Linux OSEPSS 0.1%CVE-2025-27063HIGHUse After Free in VideoEPSS 0.1%CVE-2025-36934HIGHIn bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could EPSS 0.1%CVE-2026-34854MEDIUMUAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.EPSS 0.1%CVE-2023-21020MEDIUMIn registerSignalHandlers of main.c, there is a possible local arbitrary code execution due to a use after free. This could lead to local esEPSS 0.1%CVE-2023-21043MEDIUMIn (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with EPSS 0.1%CVE-2023-40114HIGHIn multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalaEPSS 0.1%CVE-2023-21042MEDIUMIn (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with EPSS 0.1%CVE-2023-20744MEDIUMIn vcu, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privEPSS 0.1%CVE-2025-58299HIGHUse After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-58093HIGHKernel use-after-free via tty ioctlsEPSS 0.1%CVE-2025-27031HIGHUse After Free in Bluetooth HOSTEPSS 0.1%CVE-2025-20707MEDIUMIn geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious aEPSS 0.1%