Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2023-6039MEDIUMKernel: use-after-free in drivers/net/usb/lan78xx.c in lan78xx_disconnectEPSS 0.3%CVE-2021-47656HIGHjffs2: fix use-after-free in jffs2_clear_xattr_subsystemEPSS 0.3%CVE-2024-53165HIGHsh: intc: Fix use-after-free bug in register_intc_controller()EPSS 0.3%CVE-2025-59189HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-88032HIGHApplication denial of service via cancellation race in reactive client-side encryption in MongoDB Java DriverEPSS 0.3%CVE-2025-44906HIGHjhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.EPSS 0.3%CVE-2026-10890HIGHUse after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap EPSS 0.3%CVE-2025-5100HIGHKL-001-2025-005: Mobile Dynamix PrinterShare Mobile Print Double-Free Memory WriteEPSS 0.3%CVE-2026-50457HIGHWindows Runtime Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-50257HIGHnetfilter: Fix use-after-free in get_info()EPSS 0.3%CVE-2026-50689HIGHWindows Clipboard Server Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-41848MEDIUMdrivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proxEPSS 0.3%CVE-2022-49136HIGHBluetooth: hci_sync: Fix queuing commands when HCI_UNREGISTER is setEPSS 0.3%CVE-2026-88097HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50385HIGHWindows Runtime Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-49568MEDIUMIllustrator | Use After Free (CWE-416)EPSS 0.3%CVE-2024-53174HIGHSUNRPC: make sure cache entry active before cache_showEPSS 0.3%CVE-2026-50458HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-26181HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61349HIGHWindows Work Folder Service Elevation of Privilege VulnerabilityEPSS 0.3%