Fallos del tipo CWE-416

5110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-43632CRITICALllama.cpp b7492–b9060 Use-After-Free in Tokenization EndpointsEPSS 0.5%CVE-2026-26311MEDIUMEnvoy HTTP: filter chain execution on reset streams causing UAF crashEPSS 0.5%CVE-2024-50085CRITICALmptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflowEPSS 0.5%CVE-2022-3586MEDIUMA flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket bEPSS 0.5%CVE-2023-21680HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-0634MEDIUMUse After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.EPSS 0.5%CVE-2025-54588HIGHEnvoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faultsEPSS 0.5%CVE-2025-62229HIGHXorg: xmayland: use-after-free in xpresentnotify structure creationEPSS 0.5%CVE-2025-26648HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-4372HIGHUse after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crEPSS 0.5%CVE-2026-8336HIGHPost-authentication use-after-free error in $_internalJsEmit and mapreduce commandsEPSS 0.5%CVE-2023-30772MEDIUMThe Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proEPSS 0.5%CVE-2026-20870HIGHWindows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-23884HIGHHeap-use-after-free in gdi_set_boundsEPSS 0.5%CVE-2026-2787HIGHUse-after-free in the DOM: Window and Location componentEPSS 0.5%CVE-2026-23883HIGHHeap-use-after-free in update_pointer_newEPSS 0.5%CVE-2026-2789HIGHUse-after-free in the Graphics: ImageLib componentEPSS 0.5%CVE-2022-41222HIGHmm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.EPSS 0.5%CVE-2023-42041HIGHPDF-XChange Editor Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-5846HIGHUse after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.5%