Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2024-30333HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30331HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30332HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30322HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-24990HIGHNGINX HTTP/3 QUIC vulnerabilityEPSS 0.9%CVE-2024-30324HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30334HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-67385HIGHMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-57092CRITICALMicrosoft Windows VMSwitch Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-69551HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-58626HIGHWindows Remote Desktop Services Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-69712HIGHWindows Key Distribution Center Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-50666HIGHWindows Remote Access Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-62818HIGHWindows Active Directory Certificate Services (AD CS) Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-23669HIGHRPC Runtime Library Remote Code Execution VulnerabilityEPSS 0.9%CVE-2022-26710HIGHA use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, EPSS 0.9%CVE-2022-26709HIGHA use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.EPSS 0.9%CVE-2022-2738—The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman EPSS 0.9%CVE-2022-3534MEDIUMLinux Kernel libbpf btf_dump.c btf_dump_name_dups use after freeEPSS 0.9%CVE-2026-25997MEDIUMFreeRDP has heap-use-after-free in xf_clipboard_format_equalEPSS 0.9%