Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-36804HIGHWindows GDI Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-54908HIGHMicrosoft PowerPoint Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-10459MEDIUMAn attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerabilitEPSS 0.6%CVE-2026-2772HIGHUse-after-free in the Audio/Video: Playback componentEPSS 0.6%CVE-2026-32942HIGHPJSIP has ICE session use-after-free race conditionsEPSS 0.6%CVE-2026-2766CRITICALUse-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-2758CRITICALUse-after-free in the JavaScript: GC componentEPSS 0.6%CVE-2026-2765CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2026-2767HIGHUse-after-free in the JavaScript: WebAssembly componentEPSS 0.6%CVE-2026-2764CRITICALJIT miscompilation, use-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-2770HIGHUse-after-free in the DOM: Bindings (WebIDL) componentEPSS 0.6%CVE-2026-2763CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2025-14321CRITICALUse-after-free in the WebRTC: Signaling componentEPSS 0.6%CVE-2025-49698HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-58718HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-2769HIGHUse-after-free in the Storage: IndexedDB componentEPSS 0.6%CVE-2024-7000HIGHUse after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gesturEPSS 0.6%CVE-2026-74944CRITICALUse-after-free in the DOM: Core & HTML componentEPSS 0.6%CVE-2026-67300HIGHFreeRDP before 3.29.0 Use-After-Free via async message proxyEPSS 0.6%CVE-2024-4770HIGHWhen saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126,EPSS 0.6%