Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-0084HIGHIn multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over BluetoEPSS 0.2%CVE-2023-40115CRITICALIn readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of priviEPSS 0.2%CVE-2023-20937HIGHIn several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. This could lead to locaEPSS 0.2%CVE-2022-48670HIGHpeci: cpu: Fix use-after-free in adev_release()EPSS 0.2%CVE-2026-28984MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadEPSS 0.2%CVE-2025-61802HIGHSubstance3D - Stager | Use After Free (CWE-416)EPSS 0.2%CVE-2023-42870HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app mEPSS 0.2%CVE-2025-54281HIGHAdobe Framemaker | Use After Free (CWE-416)EPSS 0.2%CVE-2025-4516MEDIUMUse-after-free in "unicode_escape" decoder with error handlerEPSS 0.2%CVE-2026-32091HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2024-35843HIGHiommu/vt-d: Use device rbtree in iopf reporting pathEPSS 0.2%CVE-2025-36940HIGHUse-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (EPSS 0.2%CVE-2025-54242HIGHPremiere Pro | Use After Free (CWE-416)EPSS 0.2%CVE-2025-21671HIGHzram: fix potential UAF of zram tableEPSS 0.2%CVE-2026-74973MEDIUMRace condition, use-after-free in the Graphics componentEPSS 0.2%CVE-2026-103630—Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via EPSS 0.2%CVE-2026-103624HIGHUse after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the rEPSS 0.2%CVE-2023-3159MEDIUMA use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker EPSS 0.2%CVE-2026-103623—Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandboxEPSS 0.2%CVE-2025-21934HIGHrapidio: fix an API misues when rio_add_net() failsEPSS 0.2%