Fallos del tipo CWE-416

5110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2023-39488HIGHPDF-XChange Editor TIF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-21855HIGHibmvnic: Don't reference skb after sending to VIOSEPSS 0.4%CVE-2022-2318—There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kerneEPSS 0.4%CVE-2022-0216—A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeateEPSS 0.4%CVE-2024-38136HIGHWindows Resource Manager PSM Service Extension Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-8639HIGHUse after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruptEPSS 0.4%CVE-2025-62408MEDIUMc-ares has a Use After Free vulnerability when connection is cleaned up after errorEPSS 0.4%CVE-2024-38158HIGHAzure IoT SDK Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-39491HIGHPDF-XChange Editor TIF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-87504CRITICALUse after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary EPSS 0.4%CVE-2026-87609CRITICALUse after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the EPSS 0.4%CVE-2026-87526CRITICALUse after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially eEPSS 0.4%CVE-2026-57236LOWNokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exceptionEPSS 0.4%CVE-2026-78133HIGHlibcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.EPSS 0.4%CVE-2023-43842HIGHIncorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated EPSS 0.4%CVE-2026-79064CRITICALUse after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execuEPSS 0.4%CVE-2026-79026CRITICALUse after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially EPSS 0.4%CVE-2026-79129CRITICALUse after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to EPSS 0.4%CVE-2023-0799MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-service via a crafted EPSS 0.4%CVE-2016-9401MEDIUMpopd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.EPSS 0.4%