Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-31498HIGHc-ares has a use-after-free in read_answers()EPSS 0.6%CVE-2025-54904HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-6754HIGHUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2025-54903HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-6746HIGHUse-after-free in the DOM: Core & HTML componentEPSS 0.6%CVE-2026-6747HIGHUse-after-free in the WebRTC componentEPSS 0.6%CVE-2023-0932HIGHUse after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in sEPSS 0.6%CVE-2025-54902HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-54896HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-0927HIGHUse after free in Web Payments API in Google Chrome on Android prior to 110.0.5481.177 allowed a remote attacker who had compromised the renEPSS 0.6%CVE-2026-48090MEDIUMEnvoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)EPSS 0.6%CVE-2026-90793MEDIUMGPAC MP4Box base_scenegraph.c gf_node_get_name use after freeEPSS 0.6%CVE-2026-87464CRITICALUse after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via EPSS 0.6%CVE-2025-43536MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS EPSS 0.6%CVE-2026-58185HIGHApache Traffic Server: Use-after-free in the intercept pluginEPSS 0.6%CVE-2025-25568CRITICALSoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier dEPSS 0.6%CVE-2026-69876HIGHWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-25199HIGHInappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humbEPSS 0.6%CVE-2026-18692HIGHUse-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code ExecutionEPSS 0.6%CVE-2020-14363HIGHAn integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an appEPSS 0.6%