Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2023-3863MEDIUMUse-after-free in nfc_llcp_find_loca in net/nfc/llcp_core.cEPSS 0.2%CVE-2025-21999HIGHproc: fix UAF in proc_get_inode()EPSS 0.2%CVE-2025-8837MEDIUMJasPer JPEG2000 File jpc_dec.c jpc_dec_dump use after freeEPSS 0.2%CVE-2026-14398CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2023-52800MEDIUMwifi: ath11k: fix htt pktlog lockingEPSS 0.2%CVE-2025-21722HIGHnilfs2: do not force clear folio if buffer is referencedEPSS 0.2%CVE-2026-14419CRITICALUse after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a craftEPSS 0.2%CVE-2022-48754HIGHphylib: fix potential use-after-freeEPSS 0.2%CVE-2023-1990MEDIUMA use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux Kernel. This flaw could allow an attacker to crash EPSS 0.2%CVE-2024-57959MEDIUMUse-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to performEPSS 0.2%CVE-2026-17811HIGHUse after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escapeEPSS 0.2%CVE-2026-12455HIGHUse after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UIEPSS 0.2%CVE-2026-12015MEDIUMUse after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obEPSS 0.2%CVE-2026-54522LOWMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer DisclosureEPSS 0.2%CVE-2026-84783HIGHUse-After-Free in X.509 Extension Cache Under Concurrent UseEPSS 0.2%CVE-2022-49127HIGHref_tracker: implement use-after-free detectionEPSS 0.2%CVE-2026-14425CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2025-8842MEDIUMNASM Netwide Assember preproc.c do_directive use after freeEPSS 0.2%CVE-2025-21969HIGHBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmdEPSS 0.2%CVE-2023-52446HIGHbpf: Fix a race condition between btf_put() and map_free()EPSS 0.2%