Fallos del tipo CWE-416

5134 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-24869HIGHUse-after-free in the Layout: Scrolling and Overflow componentEPSS 0.3%CVE-2026-25171HIGHWindows Authentication Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-25170HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-2327HIGHUse-after-free in io_uring ad work_flags in Linux KernelEPSS 0.3%CVE-2026-25178HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-32914HIGHA use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, wEPSS 0.3%CVE-2026-11643HIGHUse after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network tEPSS 0.3%CVE-2023-0240HIGHUse after free in io_uring in the Linux KernelEPSS 0.3%CVE-2024-56672HIGHblk-cgroup: Fix UAF in blkcg_unpin_online()EPSS 0.3%CVE-2025-61814HIGHInDesign Desktop | Use After Free (CWE-416)EPSS 0.3%CVE-2025-61815HIGHInDesign Desktop | Use After Free (CWE-416)EPSS 0.3%CVE-2025-1290HIGHA race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. ConcurEPSS 0.3%CVE-2026-12462HIGHUse after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execuEPSS 0.3%CVE-2022-49359HIGHdrm/panfrost: Job should reference MMU not file_privEPSS 0.3%CVE-2021-33641HIGHWhen processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memoryEPSS 0.3%CVE-2023-32269MEDIUMAn issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because accept is also allowEPSS 0.3%CVE-2022-49390HIGHmacsec: fix UAF bug for real_devEPSS 0.3%CVE-2023-23586MEDIUMUse after free in io_uring in the Linux KernelEPSS 0.3%CVE-2024-56538HIGHdrm: zynqmp_kms: Unplug DRM device before removalEPSS 0.3%CVE-2024-50269HIGHusb: musb: sunxi: Fix accessing an released usb phyEPSS 0.3%