Fallos del tipo CWE-416

5110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-49761HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2021-20226—A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of servicEPSS 0.4%CVE-2024-23142HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2026-74937HIGHUse-after-free in the JavaScript: GC componentEPSS 0.4%CVE-2026-84123HIGHPrivilege escalation due to use-after-free in the Graphics: WebGPU componentEPSS 0.4%CVE-2024-34117HIGHAdobe Photoshop 2024 MPO File Parsing Use-After-Free vulnerabilityEPSS 0.4%CVE-2023-38216MEDIUMZDI-CAN-21404: Adobe Bridge Font Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-21551HIGHMicrosoft Cryptographic Services Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-4725CRITICALSandbox escape due to use-after-free in the Graphics: Canvas2D componentEPSS 0.4%CVE-2023-42364MEDIUMA use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evalEPSS 0.4%CVE-2025-0151HIGHZoom Apps - Use After FreeEPSS 0.4%CVE-2022-1198—A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by siEPSS 0.4%CVE-2023-42108HIGHPDF-XChange Editor EMF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-37355LOWKofax Power PDF JPG File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2018-14619MEDIUMA flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when eachEPSS 0.4%CVE-2026-53071HIGHBluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rspEPSS 0.4%CVE-2026-64783HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS TaEPSS 0.4%CVE-2023-21756HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-71847HIGHRuby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streamsEPSS 0.4%CVE-2023-2236HIGHUse-after-free in Linux kernel's Performance Events subsystemEPSS 0.4%