Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2023-3317HIGHA use-after-free flaw was found in mt7921_check_offload_capability in drivers/net/wireless/mediatek/mt76/mt7921/init.c in wifi mt76/mt7921 sEPSS 0.2%CVE-2024-56658HIGHnet: defer final 'struct net' free in netns dismantleEPSS 0.2%CVE-2023-46691HIGHUse after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation oEPSS 0.2%CVE-2024-38588HIGHftrace: Fix possible use-after-free issue in ftrace_location()EPSS 0.2%CVE-2023-24581HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (AEPSS 0.2%CVE-2023-25006HIGHA malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which could result in codEPSS 0.2%CVE-2023-52931HIGHdrm/i915: Avoid potential vm use-after-freeEPSS 0.2%CVE-2025-48798HIGHGimp: multiple use after free in xcf parserEPSS 0.2%CVE-2024-56582HIGHbtrfs: fix use-after-free in btrfs_encoded_read_endio()EPSS 0.2%CVE-2024-56603HIGHnet: af_can: do not leave a dangling sk pointer in can_create()EPSS 0.2%CVE-2025-66585HIGHUse After Free vulnerability in AzeoTech DAQFactoryEPSS 0.2%CVE-2025-26603MEDIUMheap-use-after-free in function str_to_reg in vim/vimEPSS 0.2%CVE-2026-11303HIGHUse after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.2%CVE-2024-50121HIGHnfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_netEPSS 0.2%CVE-2024-56581HIGHbtrfs: ref-verify: fix use-after-free after invalid ref actionEPSS 0.2%CVE-2021-47456HIGHcan: peak_pci: peak_pci_remove(): fix UAFEPSS 0.2%CVE-2025-23280HIGHNVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerEPSS 0.2%CVE-2024-53194HIGHPCI: Fix use-after-free of slot->bus on hot removeEPSS 0.2%CVE-2023-2680HIGHDma reentrancy issue (incomplete fix for cve-2021-3750)EPSS 0.2%CVE-2026-10663MEDIUMUse-after-free / double-free of the root USB device in the experimental USB host stackEPSS 0.2%