Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2022-46282HIGHUse after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specEPSS 0.2%CVE-2026-91095MEDIUMIn proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStEPSS 0.2%CVE-2024-26875MEDIUMmedia: pvrusb2: fix uaf in pvr2_context_set_notifyEPSS 0.2%CVE-2022-2977—A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configEPSS 0.2%CVE-2023-51043HIGHIn the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic comEPSS 0.2%CVE-2026-91747LOWUse after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain EPSS 0.2%CVE-2026-38753MEDIUMA use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplyEPSS 0.2%CVE-2026-12008HIGHUse after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2024-26939HIGHdrm/i915/vma: Fix UAF on destroy against retire raceEPSS 0.2%CVE-2025-2913MEDIUMHDF5 H5FL.c H5FL__blk_gc_list use after freeEPSS 0.2%CVE-2026-13029HIGHUse after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a maliciouEPSS 0.2%CVE-2026-69410HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-7976HIGHUse after free in Views in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension toEPSS 0.2%CVE-2025-37838HIGHHSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race ConditionEPSS 0.2%CVE-2026-12011HIGHUse after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2026-69430HIGHWindows Embedded Mode Service Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-62573HIGHDirectX Graphics Kernel Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2023-27969HIGHA use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iEPSS 0.2%CVE-2023-52752HIGHsmb: client: fix use-after-free bug in cifs_debug_data_proc_show()EPSS 0.2%CVE-2023-1652HIGHA use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allEPSS 0.2%