Weaknesses of type CWE-416

5,184 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-47327HIGHUse After Free in CameraEPSS 0.1%CVE-2025-47354HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2025-47350HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2024-40651HIGHIn TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the EPSS 0.1%CVE-2024-40649HIGHIn TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the EPSS 0.1%CVE-2025-54626MEDIUMPointer dangling vulnerability in the cjwindow module. Impact: Successful exploitation of this vulnerability may affect function stability.EPSS 0.1%CVE-2025-47337MEDIUMUse After Free in Camera DriverEPSS 0.1%CVE-2025-47336MEDIUMUse After Free in Camera DriverEPSS 0.1%CVE-2025-20779HIGHIn display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actoEPSS 0.1%CVE-2023-40107HIGHIn ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilEPSS 0.1%CVE-2025-22407MEDIUMIn hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to locEPSS 0.1%CVE-2023-48353MEDIUMIn vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution priEPSS 0.1%CVE-2024-23658MEDIUMIn camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution EPSS 0.1%CVE-2018-9439HIGHIn __unregister_prot_hook and packet_release of af_packet.c, there is a possible use-after-free due to improper locking. This could leadEPSS 0.1%CVE-2025-20744MEDIUMIn pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious aEPSS 0.1%CVE-2025-20743MEDIUMIn clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a maliciouEPSS 0.1%CVE-2025-20787MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20770MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20805MEDIUMIn dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor hEPSS 0.1%CVE-2025-20775MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%