Fallos del tipo CWE-416

5111 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-79194HIGHUse after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outsiEPSS 0.4%CVE-2026-13787HIGHUse after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via maliEPSS 0.4%CVE-2026-79039HIGHUse after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sEPSS 0.4%CVE-2025-62504MEDIUMEnvoy Lua filter use-after-free when oversized rewritten response body causes crashEPSS 0.4%CVE-2026-13071HIGHServer-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process TerminationEPSS 0.4%CVE-2026-56434HIGHNGINX ngx_http_ssi_module vulnerabilityEPSS 0.4%CVE-2022-41663HIGHA vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamceEPSS 0.4%CVE-2024-0752MEDIUMA use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted iEPSS 0.4%CVE-2023-3567HIGHKernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to raceEPSS 0.4%CVE-2024-34100HIGHUse-After-Free vulnerability in the latest Adobe Acrobat Reader DC when open malicious PDF fileEPSS 0.4%CVE-2024-37007HIGHMultiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based productsEPSS 0.4%CVE-2023-4921HIGHUse-after-free in Linux kernel's net/sched: sch_qfq componentEPSS 0.4%CVE-2025-53730HIGHMicrosoft Office Visio Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-46523MEDIUMImageMagick: Use-After-Free in MSL decoder.EPSS 0.4%CVE-2019-3896HIGHA double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw fEPSS 0.4%CVE-2023-39198HIGHKernel: qxl: race condition leading to use-after-free in qxl_mode_dumb_create()EPSS 0.4%CVE-2023-36565HIGHMicrosoft Office Graphics Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-53132HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-6784HIGHMemory safety bugs fixed in Firefox 150 and Thunderbird 150EPSS 0.4%CVE-2025-59236HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.4%