Fallos del tipo CWE-416

5134 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2021-42706HIGHAzeoTech DAQFactoryEPSS 0.3%CVE-2022-49388HIGHubi: ubi_create_volume: Fix use-after-free when volume creation failedEPSS 0.3%CVE-2026-55318HIGHIn multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additionEPSS 0.3%CVE-2022-49695HIGHigb: fix a use-after-free issue in igb_clean_tx_ringEPSS 0.3%CVE-2025-54223HIGHInCopy | Use After Free (CWE-416)EPSS 0.3%CVE-2024-46740HIGHbinder: fix UAF caused by offsets overwriteEPSS 0.3%CVE-2022-49667HIGHnet: bonding: fix use-after-free after 802.3ad slave unbindEPSS 0.3%CVE-2025-54108HIGHCapability Access Management Service (camsvc) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-49411HIGHbfq: Make sure bfqg for which we are queueing requests is onlineEPSS 0.3%CVE-2022-49647HIGHcgroup: Use separate src/dst nodes when preloading css_sets for migrationEPSS 0.3%CVE-2022-49413HIGHbfq: Update cgroup information before merging bioEPSS 0.3%CVE-2025-53807HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-1973—A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attackerEPSS 0.3%CVE-2024-53239HIGHALSA: 6fire: Release resources at card releaseEPSS 0.3%CVE-2022-1184—A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a locaEPSS 0.3%CVE-2024-56631HIGHscsi: sg: Fix slab-use-after-free read in sg_release()EPSS 0.3%CVE-2023-31974MEDIUMyasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third parties dispute this EPSS 0.3%CVE-2025-59210HIGHWindows Resilient File System (ReFS) Deduplication Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-49426HIGHiommu/arm-smmu-v3-sva: Fix mm use-after-freeEPSS 0.3%CVE-2022-49696HIGHtipc: fix use-after-free Read in tipc_named_reinitEPSS 0.3%