Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-69579CRITICALWindows Message Queuing Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-73010CRITICALMicrosoft Failover Cluster Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-69595CRITICALWindows Services for NFS ONCRPC XDR Driver Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-45657CRITICALWindows Kernel Remote Code Execution VulnerabilityEPSS 1.0%CVE-2023-25361HIGHA use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKitGTK before 2.36.8 allows attackers to execute code remotely.EPSS 1.0%CVE-2026-72979CRITICALWindows DHCP Server Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-62893CRITICALWindows Deployment Services TFTP Server Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-72983CRITICALInternet Connection Sharing (ICS) Remote Code Execution VulnerabilityEPSS 1.0%CVE-2024-26592CRITICALksmbd: fix UAF issue in ksmbd_tcp_new_connection()EPSS 1.0%CVE-2024-2612HIGHIf an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveragEPSS 1.0%CVE-2022-1106HIGHuse after free in mrb_vm_exec in mruby/mrubyEPSS 1.0%CVE-2025-29831HIGHWindows Remote Desktop Services Remote Code Execution VulnerabilityEPSS 1.0%CVE-2023-1811HIGHUse after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI intEPSS 1.0%CVE-2024-9955HIGHUse after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruptionEPSS 1.0%CVE-2024-21385HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2023-2932HIGHUse after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a craftedEPSS 1.0%CVE-2022-3046HIGHUse after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extensEPSS 1.0%CVE-2023-33657HIGHA use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_EPSS 1.0%CVE-2022-22740HIGHCertain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causiEPSS 1.0%CVE-2022-28310HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034.EPSS 1.0%