Weaknesses of type CWE-416

5,043 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2026-50460HIGHWindows Runtime Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-69827HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-49023MEDIUMMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-69782HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-2912MEDIUMSiteManager Embedded service disruptionEPSS 0.5%CVE-2026-62778HIGHWindows DNS Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-1218HIGHUse after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.5%CVE-2023-51565HIGHKofax Power PDF XPS File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-52997HIGHPhotoshop Desktop | Use After Free (CWE-416)EPSS 0.5%CVE-2026-8092HIGHMemory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2EPSS 0.5%CVE-2024-53953HIGHAnimate | Use After Free (CWE-416)EPSS 0.5%CVE-2023-51563HIGHKofax Power PDF XPS File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-1216HIGHUse after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in directEPSS 0.5%CVE-2026-90852MEDIUMluben zstd-jni Dictionary Sharing ZstdCompressCtx.java ZstdCompressCtx.loadDict use after freeEPSS 0.5%CVE-2026-94084CRITICALSuricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with EPSS 0.5%CVE-2023-53338CRITICALlwt: Fix return values of BPF xmit opsEPSS 0.5%CVE-2023-38112HIGHFoxit PDF Reader XFA Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-38117HIGHFoxit PDF Reader AcroForm Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-38111HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-38107HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%