Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-21700HIGHnet: sched: Disallow replacing of child qdisc from one parent to anotherEPSS 0.2%CVE-2026-10639MEDIUMUse-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`EPSS 0.2%CVE-2025-21786HIGHworkqueue: Put the pwq after detaching the rescuer from the poolEPSS 0.2%CVE-2024-53232HIGHiommu/s390: Implement blocking domainEPSS 0.2%CVE-2022-49755HIGHusb: gadget: f_fs: Prevent race during ffs_ep0_queue_waitEPSS 0.2%CVE-2023-1855MEDIUMA use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hEPSS 0.2%CVE-2026-22040MEDIUMNanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker CrashEPSS 0.2%CVE-2026-11642HIGHUse after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to poEPSS 0.2%CVE-2023-52921HIGHdrm/amdgpu: fix possible UAF in amdgpu_cs_pass1()EPSS 0.2%CVE-2023-4133MEDIUMKernel: cxgb4: use-after-free in ch_flower_stats_cb()EPSS 0.2%CVE-2025-61834HIGHSubstance3D - Stager | Use After Free (CWE-416)EPSS 0.2%CVE-2021-46973HIGHnet: qrtr: Avoid potential use after free in MHI sendEPSS 0.2%CVE-2025-61817HIGHInCopy | Use After Free (CWE-416)EPSS 0.2%CVE-2024-50274HIGHidpf: avoid vport access in idpf_get_link_ksettingsEPSS 0.2%CVE-2026-32724MEDIUMPX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race ConditionEPSS 0.2%CVE-2025-6119MEDIUMOpen Asset Import Library Assimp BVHLoader.cpp ReadNodeChannels use after freeEPSS 0.2%CVE-2025-61818HIGHInCopy | Use After Free (CWE-416)EPSS 0.2%CVE-2026-56373MEDIUMImageMagick - Use-After-Free Write in PDB DecoderEPSS 0.2%CVE-2025-21731HIGHnbd: don't allow reconnect after disconnectEPSS 0.2%CVE-2024-50126HIGHnet: sched: use RCU read-side critical section in taprio_dump()EPSS 0.2%