Fallos del tipo CWE-416

5129 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-9883HIGHUse after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page.EPSS 0.4%CVE-2026-85049HIGHUse after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a EPSS 0.4%CVE-2026-19560HIGHUse after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2026-14006HIGHUse after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML EPSS 0.4%CVE-2024-8821LOWPDF-XChange Editor U3D File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2022-42414LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.4%CVE-2025-8292HIGHUse after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption viaEPSS 0.4%CVE-2026-23657HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-7010HIGHUse after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.4%CVE-2026-0885MEDIUMUse-after-free in the JavaScript: GC componentEPSS 0.4%CVE-2025-47976HIGHWindows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-1144MEDIUMquickjs-ng quickjs Atomics Ops quickjs.c use after freeEPSS 0.4%CVE-2025-54103HIGHWindows Management Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-43731HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2026-43715HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, iOEPSS 0.4%CVE-2023-6270HIGHKernel: aoe: improper reference count leads to use-after-free vulnerabilityEPSS 0.4%CVE-2021-43753HIGHAdobe Lightroom TIF File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2022-38447HIGHAdobe Dimension SKP File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-38446HIGHAdobe Dimension SKP File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-38448HIGHAdobe Dimension SKP File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%