Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-11152CRITICALObject lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape viaEPSS 0.2%CVE-2026-11071HIGHUse after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process tEPSS 0.2%CVE-2026-11663HIGHUse after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.2%CVE-2026-21326HIGHAfter Effects | Use After Free (CWE-416)EPSS 0.2%CVE-2026-21221HIGHCapability Access Management Service (camsvc) Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-11188HIGHUse after free in USB in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape vEPSS 0.2%CVE-2026-21329HIGHAfter Effects | Use After Free (CWE-416)EPSS 0.2%CVE-2026-11177HIGHUse after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI geEPSS 0.2%CVE-2026-21320HIGHAfter Effects | Use After Free (CWE-416)EPSS 0.2%CVE-2022-49753HIGHdmaengine: Fix double increment of client_count in dma_chan_get()EPSS 0.2%CVE-2024-50051HIGHspi: mpc52xx: Add cancel_work_sync before module removeEPSS 0.2%CVE-2024-11155HIGHRockwell Automation Arena® Use After Free VulnerabilityEPSS 0.2%CVE-2024-50186HIGHnet: explicitly clear the sk pointer, when pf->create failsEPSS 0.2%CVE-2021-47068HIGHnet/nfc: fix use-after-free llcp_sock_bind/connectEPSS 0.2%CVE-2025-21786HIGHworkqueue: Put the pwq after detaching the rescuer from the poolEPSS 0.2%CVE-2026-10639MEDIUMUse-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`EPSS 0.2%CVE-2026-11633HIGHUse after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a maliciEPSS 0.2%CVE-2022-49755HIGHusb: gadget: f_fs: Prevent race during ffs_ep0_queue_waitEPSS 0.2%CVE-2024-57984HIGHi3c: dw: Fix use-after-free in dw_i3c_master driver due to race conditionEPSS 0.2%CVE-2024-21918HIGHRockwell Automation Arena Simulation Vulnerable To Memory CorruptionEPSS 0.2%