Fallos del tipo CWE-416

5129 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2024-21860HIGHDsoftbus has a use after free vulnerabilityEPSS 0.4%CVE-2025-0072HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.4%CVE-2025-46205HIGHA heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of ServicEPSS 0.4%CVE-2026-79247HIGHUse after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the rendereEPSS 0.4%CVE-2026-44805MEDIUMWindows Network Controller (NC) Host Agent Denial of Service VulnerabilityEPSS 0.4%CVE-2025-5958HIGHUse after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.4%CVE-2025-3066HIGHUse after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption viEPSS 0.4%CVE-2024-9243HIGHFoxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-50363CRITICALskmsg: pass gfp argument to alloc_sk_msg()EPSS 0.4%CVE-2025-58719MEDIUMWindows Connected Devices Platform Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-30031HIGHWindows CNG Key Isolation Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-67299HIGHFreeRDP before 3.29.0 Use-After-Free via WindowIcon async messageEPSS 0.4%CVE-2023-49554MEDIUMUse After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in tEPSS 0.4%CVE-2022-1934MEDIUMUse After Free in mruby/mrubyEPSS 0.4%CVE-2026-4711CRITICALUse-after-free in the Widget: Cocoa componentEPSS 0.4%CVE-2026-3921HIGHUse after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.4%CVE-2025-59290HIGHWindows Bluetooth Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-44095—Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vulnerability can cause system crash.EPSS 0.4%CVE-2026-12442HIGHUse after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crEPSS 0.4%CVE-2026-20865HIGHWindows Management Services Elevation of Privilege VulnerabilityEPSS 0.4%