Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2021-22545HIGHUse-after-free in BinDiffEPSS 0.2%CVE-2026-11154HIGHUse after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.2%CVE-2025-33220HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the mEPSS 0.2%CVE-2024-9979MEDIUMPyo3: risk of use-after-free in `borrowed` reads from python weak referencesEPSS 0.2%CVE-2023-32378HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOSEPSS 0.2%CVE-2026-11201HIGHUse after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious exteEPSS 0.2%CVE-2023-4891MEDIUM A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service. EPSS 0.2%CVE-2026-40290HIGHOP-TEE has a Use-After-Free race in FF-A shared-memory teardownEPSS 0.2%CVE-2023-26589MEDIUMUse after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of seEPSS 0.2%CVE-2024-58060HIGHbpf: Reject struct_ops registration that uses module ptr and the module btf_id is missingEPSS 0.2%CVE-2026-24295HIGHWindows Device Association Service Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-23671HIGHWindows Bluetooth RFCOM Protocol Driver Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-22085HIGHRDMA/core: Fix use-after-free when rename device nameEPSS 0.2%CVE-2025-21923HIGHHID: hid-steam: Fix use-after-free when detaching deviceEPSS 0.2%CVE-2025-21867HIGHbpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()EPSS 0.2%CVE-2025-21879HIGHbtrfs: fix use-after-free on inode when scanning root during em shrinkingEPSS 0.2%CVE-2022-50413HIGHwifi: mac80211: fix use-after-freeEPSS 0.2%CVE-2025-61662HIGHGrub2: missing unregister call for gettext command may lead to use-after-freeEPSS 0.2%CVE-2022-20566HIGHIn l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking. This could lead to local escalation of privilegEPSS 0.2%CVE-2025-61842MEDIUMFormat Plugins | Use After Free (CWE-416)EPSS 0.2%