Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2022-43286CRITICALNginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_cEPSS 1.0%CVE-2022-3039HIGHUse after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 1.0%CVE-2022-43641LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. UseEPSS 1.0%CVE-2023-33876HIGHA use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. Specially crafted Javascript codeEPSS 1.0%CVE-2024-4948HIGHUse after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafteEPSS 1.0%CVE-2022-43716HIGHA vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-EPSS 1.0%CVE-2026-50432MEDIUMWindow Virtual Filtering Platform (VFP) Denial of Service VulnerabilityEPSS 1.0%CVE-2026-25953MEDIUMFreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (freed appWindow)EPSS 1.0%CVE-2026-25952MEDIUMFreeRDP has heap-use-after-free in xf_SetWindowMinMaxInfoEPSS 1.0%CVE-2024-1059HIGHUse after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruptionEPSS 1.0%CVE-2023-1999MEDIUMUse after free in libwebpEPSS 1.0%CVE-2025-26630HIGHMicrosoft Access Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-3805HIGHuse after free in SMB connection reuseEPSS 1.0%CVE-2022-28303HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.16.02.022. User interactioEPSS 1.0%CVE-2024-38249HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2021-29093MEDIUMArcGIS Server image service and raster analytics security update: use-after-freeEPSS 0.9%CVE-2026-29167CRITICALApache HTTP Server: mod_ldap per-dir use-after-freeEPSS 0.9%CVE-2022-23459HIGHDouble free or Use after Free in Value class of JsonxxEPSS 0.9%CVE-2024-4949CRITICALUse after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted EPSS 0.9%CVE-2020-4060MEDIUMUse After Free in in cups_update_info in LoRa Basics StationEPSS 0.9%