Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2022-49047HIGHep93xx: clock: Fix UAF in ep93xx_clk_register_gate()EPSS 0.2%CVE-2024-6519HIGHQemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerabilityEPSS 0.2%CVE-2025-59220HIGHWindows Bluetooth Service Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-59216HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2023-2162MEDIUMA use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux KerneEPSS 0.2%CVE-2023-52447HIGHbpf: Defer the free of inner map when necessaryEPSS 0.2%CVE-2025-20006HIGHUse after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentEPSS 0.2%CVE-2022-49669HIGHmptcp: fix race on unaccepted mptcp socketsEPSS 0.2%CVE-2026-92060HIGHUse-after-free in the Internationalization componentEPSS 0.2%CVE-2026-92067HIGHUse-after-free in the Widget: Gtk componentEPSS 0.2%CVE-2026-14390CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2026-92049HIGHUse-after-free in the Widget: Win32 componentEPSS 0.2%CVE-2026-92058HIGHUse-after-free in the Graphics componentEPSS 0.2%CVE-2023-3472HIGHUse after free vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.EPSS 0.2%CVE-2026-92056HIGHUse-after-free in the Graphics: Text componentEPSS 0.2%CVE-2026-100825HIGHUse-after-free in the JavaScript Engine: JIT componentEPSS 0.2%CVE-2025-6856MEDIUMHDF5 H5FL.c H5FL__reg_gc_list use after freeEPSS 0.2%CVE-2026-100815HIGHUse-after-free in the CSS Parsing and Computation componentEPSS 0.2%CVE-2023-51043HIGHIn the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic comEPSS 0.2%CVE-2024-26875MEDIUMmedia: pvrusb2: fix uaf in pvr2_context_set_notifyEPSS 0.2%