Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2022-3239—A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based EPSS 0.3%CVE-2024-39463HIGH9p: add missing locking around taking dentry fid listEPSS 0.3%CVE-2025-54279HIGHAnimate | Use After Free (CWE-416)EPSS 0.3%CVE-2024-12175HIGHRockwell Automation Code Execution Vulnerability in ArenaEPSS 0.3%CVE-2026-100831HIGHUse-after-free in the DOM: UI Events & Focus Handling componentEPSS 0.3%CVE-2022-49087HIGHrxrpc: fix a race in rxrpc_exit_net()EPSS 0.3%CVE-2026-33023HIGHlibsixel: Use-after-free in load_with_gdkpixbuf()EPSS 0.3%CVE-2023-4132MEDIUMKernel: smsusb: use-after-free caused by do_submit_urb()EPSS 0.3%CVE-2026-2321HIGHUse after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestEPSS 0.3%CVE-2023-52838MEDIUMfbdev: imsttfb: fix a resource leak in probeEPSS 0.3%CVE-2021-47639HIGHKVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMUEPSS 0.3%CVE-2026-4458HIGHUse after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convinced a user to install a malicious extensEPSS 0.3%CVE-2024-53168HIGHsunrpc: fix one UAF issue caused by sunrpc kernel tcp socketEPSS 0.3%CVE-2026-11654CRITICALUse after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox eEPSS 0.3%CVE-2026-11657HIGHUse after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a craftedEPSS 0.3%CVE-2026-11630HIGHUse after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.3%CVE-2025-12438HIGHUse after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to potentially exploit objecEPSS 0.3%CVE-2020-22429HIGHredox-os v0.1.0 was discovered to contain a use-after-free bug via the gethostbyaddr() function at /src/header/netdb/mod.rs.EPSS 0.3%CVE-2026-11634CRITICALUse after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escEPSS 0.3%CVE-2026-12310HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%