Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2023-2680HIGHDma reentrancy issue (incomplete fix for cve-2021-3750)EPSS 0.2%CVE-2024-50121HIGHnfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_netEPSS 0.2%CVE-2021-47668HIGHcan: dev: can_restart: fix use after free bugEPSS 0.2%CVE-2022-1976—A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable permission to create aEPSS 0.2%CVE-2026-9877HIGHUse after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potenEPSS 0.2%CVE-2026-9925HIGHUse after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potenEPSS 0.2%CVE-2024-35801HIGHx86/fpu: Keep xfd_state in sync with MSR_IA32_XFDEPSS 0.2%CVE-2026-11040HIGHUse after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.2%CVE-2024-50067HIGHuprobe: avoid out-of-bounds memory access of fetching argsEPSS 0.2%CVE-2026-11082CRITICALRace in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.2%CVE-2026-11131CRITICALUse after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2022-48674HIGHerofs: fix pcluster use-after-free on UP platformsEPSS 0.2%CVE-2026-11114CRITICALUse after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2024-32610MEDIUMHDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.EPSS 0.2%CVE-2026-11163CRITICALUse after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escEPSS 0.2%CVE-2026-11080HIGHUse after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruptioEPSS 0.2%CVE-2026-11165CRITICALUse after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape vEPSS 0.2%CVE-2026-11094CRITICALUse after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proceEPSS 0.2%CVE-2026-21351HIGHAfter Effects | Use After Free (CWE-416)EPSS 0.2%CVE-2026-21323HIGHAfter Effects | Use After Free (CWE-416)EPSS 0.2%