Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-21631HIGHblock, bfq: fix waker_bfqq UAF after bfq_split_bfqq()EPSS 0.2%CVE-2026-64718MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, Safari 27, iOS 26.6 and iPadOS 26.EPSS 0.2%CVE-2024-14028MEDIUMMultiple implicit reads in parallel can result in a crash or denial of serviceEPSS 0.2%CVE-2026-21287HIGHSubstance3D - Stager | Use After Free (CWE-416)EPSS 0.2%CVE-2025-21652HIGHipvlan: Fix use-after-free in ipvlan_get_iflink().EPSS 0.2%CVE-2023-3397HIGHKernel: slab-use-after-free write in txend due to race conditionEPSS 0.2%CVE-2024-8422HIGHCWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & inteEPSS 0.2%CVE-2024-57887HIGHdrm: adv7511: Fix use-after-free in adv7533_attach_dsi()EPSS 0.2%CVE-2023-53322HIGHscsi: qla2xxx: Wait for io return on terminate rportEPSS 0.2%CVE-2024-32929HIGHIn gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege EPSS 0.2%CVE-2024-50084HIGHnet: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()EPSS 0.2%CVE-2024-56765HIGHpowerpc/pseries/vas: Add close() callback in vas_vm_ops structEPSS 0.2%CVE-2025-6555MEDIUMUse after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.2%CVE-2025-46710MEDIUMPossible kernel exceptions caused by reading and writing kernel heap data after free.EPSS 0.2%CVE-2023-1195MEDIUMA use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgetEPSS 0.2%CVE-2025-54335MEDIUMAn issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the XclipsEPSS 0.2%CVE-2026-11154HIGHUse after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.2%CVE-2021-22545HIGHUse-after-free in BinDiffEPSS 0.2%CVE-2026-102760HIGHWhen NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. BEPSS 0.2%CVE-2025-22068HIGHublk: make sure ubq->canceling is set when queue is frozenEPSS 0.2%