Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-62819HIGHWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-2400HIGHUse after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruptEPSS 0.7%CVE-2024-24263HIGHLotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotosEPSS 0.7%CVE-2024-24262HIGHmedia-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transEPSS 0.7%CVE-2024-24260HIGHmedia-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subEPSS 0.7%CVE-2023-24953HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.7%CVE-2021-30469—A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PEPSS 0.7%CVE-2026-5281HIGHUse after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to executEPSS 0.7%KEVCVE-2022-48686CRITICALnvme-tcp: fix UAF when detecting digest errorsEPSS 0.7%CVE-2023-21773HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2019-8526HIGHA use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be ablEPSS 0.7%KEVCVE-2026-50369HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-82623MEDIUMopen62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange use after freeEPSS 0.7%CVE-2023-24947HIGHWindows Bluetooth Driver Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-24082HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-20681HIGHWindows Subsystem for Linux Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2022-46394HIGHAn issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access EPSS 0.7%CVE-2026-56649MEDIUMWindows Network File System Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-35351MEDIUMWindows Active Directory Certificate Services (AD CS) Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-32541HIGHA use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially crafted .doc file caEPSS 0.7%