Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-5574HIGHXorg-x11-server: use-after-free bug in damagedestroyEPSS 0.6%CVE-2025-29977HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-49703HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2022-3309MEDIUMUse after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in EPSS 0.6%CVE-2024-54499HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tEPSS 0.6%CVE-2024-35870CRITICALsmb: client: fix UAF in smb2_reconnect_server()EPSS 0.6%CVE-2024-9255HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-7722LOWFoxit PDF Reader Doc Object Use-After-Free Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-9250HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.6%CVE-2022-40639HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2021-47232CRITICALcan: j1939: fix Use-after-Free, hold skb ref while in useEPSS 0.6%CVE-2022-40638HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2024-6997HIGHUse after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestuEPSS 0.6%CVE-2025-62563HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-6998HIGHUse after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specifiEPSS 0.6%CVE-2024-6292HIGHUse after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a craftEPSS 0.6%CVE-2024-3856HIGHA use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects FirEPSS 0.6%CVE-2026-12443HIGHUse after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafEPSS 0.6%CVE-2023-4622HIGHUse-after-free in Linux kernel's af_unix componentEPSS 0.6%CVE-2024-56640CRITICALnet/smc: fix LGR and link use-after-free issueEPSS 0.6%