Fallos del tipo CWE-416

5130 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2022-1050—A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commaEPSS 0.4%CVE-2026-27220HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-21921HIGHJunos OS and Junos OS Evolved: When telemetry collectors are frequently subscribing and unsubscribing to sensors chassisd or rpd will crashEPSS 0.4%CVE-2023-26410HIGHZDI-CAN-20309: Adobe Substance 3D Designer USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-26392HIGHZDI-CAN-20235: Adobe Substance 3D Stager USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-26414HIGHZDI-CAN-20316: Adobe Substance 3D Designer USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-52115HIGHThe iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.EPSS 0.4%CVE-2024-30416HIGHUse After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation of this vulnerability will affect availaEPSS 0.4%CVE-2020-5348MEDIUMDell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A loEPSS 0.4%CVE-2026-34771HIGHElectron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacksEPSS 0.4%CVE-2023-26384HIGHZDI-CAN-20279: Adobe Substance 3D Stager USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-25871HIGHAdobe Substance 3D Stager SVG File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-43699MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2026-43720MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2024-2312MEDIUMGRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks afterEPSS 0.4%CVE-2026-95335HIGHUse after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentiaEPSS 0.4%CVE-2025-48806HIGHMicrosoft MPEG-2 Video Extension Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-49675HIGHKernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-59206HIGHWindows Resilient File System (ReFS) Deduplication Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-49660HIGHWindows Event Tracing Elevation of Privilege VulnerabilityEPSS 0.4%