Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2022-3885HIGHUse after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a craftedEPSS 0.8%CVE-2023-21747HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2022-0615MEDIUMUse-after-free vulnerability in ESET products for LinuxEPSS 0.8%CVE-2020-14381HIGHA flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their prEPSS 0.8%CVE-2022-3055HIGHUse after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI EPSS 0.8%CVE-2026-78446MEDIUMWindows Distributed File System (DFS) Denial of Service VulnerabilityEPSS 0.8%CVE-2026-73512HIGHEnvoy: use-after-free in QUIC on internal redirectsEPSS 0.8%CVE-2022-38476HIGHA data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this EPSS 0.8%CVE-2023-42459HIGHMalformed DATA submessage leads to bad-free error in Fast-DDSEPSS 0.8%CVE-2026-50521HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-25087HIGHApache Arrow: Potential use-after-free when reading IPC file with pre-bufferingEPSS 0.8%CVE-2023-34294LOWSante DICOM Viewer Pro DCM File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.8%CVE-2023-1530HIGHUse after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafteEPSS 0.8%CVE-2026-43810CRITICALThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOEPSS 0.8%CVE-2021-0920MEDIUMIn unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privEPSS 0.8%KEVCVE-2026-42985HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-32157HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-62795HIGHWindows LDAP - Lightweight Directory Access Protocol Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-78525HIGHMicrosoft Office Outlook Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-57981HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.8%