Fallos del tipo CWE-416

5110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-4691CRITICALUse-after-free in the CSS Parsing and Computation componentEPSS 0.5%CVE-2024-5832HIGHUse after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafteEPSS 0.5%CVE-2025-48821HIGHWindows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-42040HIGHPDF-XChange Editor mailForm Use-After-Free Code Execution VulnerabilityEPSS 0.5%CVE-2023-42059HIGHPDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-0807HIGHUse after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.5%CVE-2023-42086HIGHPDF-XChange Editor EMF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-53185HIGHsmb: client: fix NULL ptr deref in crypto_aead_setkey()EPSS 0.5%CVE-2026-81934HIGHRedis TLS pending-data list use-after-freeEPSS 0.5%CVE-2024-36013HIGHBluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()EPSS 0.5%CVE-2026-68886MEDIUMWindows Network Connection Broker Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-32712HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-38428MEDIUMAdobe Photoshop DCM File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-58735HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-23135HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.5%CVE-2025-58732HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-34263HIGHAdobe Illustrator Font Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-50086CRITICALksmbd: fix user-after-free from session log offEPSS 0.5%CVE-2026-74969HIGHUse-after-free in the Layout: Text and Fonts componentEPSS 0.5%CVE-2024-8637HIGHUse after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corEPSS 0.5%