Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-10994MEDIUMOpen Babel gamessformat.cpp ReadMolecule use after freeEPSS 0.2%CVE-2025-21858HIGHgeneve: Fix use-after-free in geneve_find_dev().EPSS 0.2%CVE-2026-65341MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and EPSS 0.2%CVE-2023-1611MEDIUMA use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash EPSS 0.2%CVE-2024-3857HIGHThe JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This EPSS 0.2%CVE-2026-58543MEDIUMUniversal Print Management Service Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-11224HIGHUse after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via maliciEPSS 0.2%CVE-2024-50150HIGHusb: typec: altmode should keep reference to parentEPSS 0.2%CVE-2026-6297HIGHUse after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially performEPSS 0.2%CVE-2026-11671CRITICALUse after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via EPSS 0.2%CVE-2026-11674HIGHUse after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox vEPSS 0.2%CVE-2025-23106MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilegeEPSS 0.2%CVE-2022-2978—A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with foEPSS 0.2%CVE-2024-56558HIGHnfsd: make sure exp active before svc_export_showEPSS 0.2%CVE-2024-56601HIGHnet: inet: do not leave a dangling sk pointer in inet_create()EPSS 0.2%CVE-2024-56693HIGHbrd: defer automatic disk creation until module initialization succeedsEPSS 0.2%CVE-2026-11673HIGHUse after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbEPSS 0.2%CVE-2025-23101MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privilege escalation.EPSS 0.2%CVE-2025-23104MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privilege escalation.EPSS 0.2%CVE-2025-6275MEDIUMWebAssembly wabt binary-reader-interp.cc GetFuncOffset use after freeEPSS 0.2%