Fallos del tipo CWE-416

5129 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-0445MEDIUMUse after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted EPSS 0.4%CVE-2023-25896HIGHZDI-CAN-19541: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-1989HIGHA use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove wiEPSS 0.4%CVE-2026-47205MEDIUMEnvoy: ext_authz Use-After-Free during Stream Teardown with Per-Route OverridesEPSS 0.4%CVE-2026-11118HIGHUse after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2023-25894HIGHZDI-CAN-19543: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-28879MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadEPSS 0.4%CVE-2023-25899HIGHZDI-CAN-19522: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-59221HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-25893HIGHZDI-CAN-19539: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-26336HIGHZDI-CAN-20275: Adobe Dimension USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-20789HIGHZDI-CAN-24030: Adobe Dimension SKP File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-42374HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2023-26544HIGHIn the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sector size and mEPSS 0.4%CVE-2023-44436HIGHKofax Power PDF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-29841HIGHUniversal Print Management Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-91721HIGHUse after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside EPSS 0.4%CVE-2023-44435HIGHKofax Power PDF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-53802HIGHWindows Bluetooth Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-86713HIGHPX4 Autopilot through 1.17.0 Use-After-Free in load_monEPSS 0.4%