Fallos del tipo CWE-416

5129 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2023-37576HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2023-44328MEDIUMZDI-CAN-21797: Adobe Bridge MP4 File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-0358HIGHUse After Free in gpac/gpacEPSS 0.4%CVE-2023-37577HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2026-22264HIGHSuricata detect/alert: heap-use-after-free on alert queue expansionEPSS 0.4%CVE-2023-37573HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2023-37575HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2026-28687MEDIUMImageMagick has a Heap Use-After-Free in ImageMagick MSL decoderEPSS 0.4%CVE-2026-18700MEDIUMUse-After-Free in MongoDB Geospatial Validation Leads to Denial of ServiceEPSS 0.4%CVE-2024-9959HIGHUse after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potEPSS 0.4%CVE-2024-11113HIGHUse after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process tEPSS 0.4%CVE-2024-43472MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-57437LOWNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetimeEPSS 0.4%CVE-2026-57436LOWNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node typeEPSS 0.4%CVE-2025-1930HIGHAudioIPC StreamData could trigger a use-after-free in the Browser processEPSS 0.4%CVE-2026-56960CRITICALIn multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilegEPSS 0.4%CVE-2021-25394MEDIUMA use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radioEPSS 0.4%KEVCVE-2022-1204—A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocoEPSS 0.4%CVE-2022-42408LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.4%CVE-2025-21372HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.4%