Weaknesses of type CWE-416

5,184 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-25985HIGHIn bigo_unlocked_ioctl of bigo.c, there is a possible UAF due to a missing bounds check. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2025-22409HIGHIn rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to localEPSS 0.1%CVE-2025-21474HIGHUse After Free in BTHOSTEPSS 0.1%CVE-2024-33040MEDIUMUse After Free in Camera DriverEPSS 0.1%CVE-2024-34748HIGHIn _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to locaEPSS 0.1%CVE-2025-32332HIGHIn multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with EPSS 0.1%CVE-2023-43543MEDIUMUse After Free in AudioEPSS 0.1%CVE-2025-21458HIGHUse After Free in NPUEPSS 0.1%CVE-2025-21456HIGHUse After Free in NPUEPSS 0.1%CVE-2025-59616MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2025-21466HIGHUse After Free in DisplayEPSS 0.1%CVE-2022-47371MEDIUMIn bt driver, there is a thread competition leads to early release of resources to be accessed. This could lead to local denial of service iEPSS 0.1%CVE-2025-59617MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2023-21165HIGHIn DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local eEPSS 0.1%CVE-2025-59615MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2025-22438HIGHIn afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local escalation of priviEPSS 0.1%CVE-2025-27037HIGHUse After Free in Camera DriverEPSS 0.1%CVE-2025-27077HIGHUse After Free in Automotive Software platform based on QNXEPSS 0.1%CVE-2025-47315HIGHUse After Free in Automotive Software platform based on QNXEPSS 0.1%CVE-2025-47327HIGHUse After Free in CameraEPSS 0.1%