Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-21968HIGHdrm/amd/display: Fix slab-use-after-free on hdcp_workEPSS 0.2%CVE-2026-84895HIGHIn proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSeEPSS 0.2%CVE-2023-52935HIGHmm/khugepaged: fix ->anon_vma raceEPSS 0.2%CVE-2022-49921HIGHnet: sched: Fix use after free in red_enqueue()EPSS 0.2%CVE-2025-15538MEDIUMOpen Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after freeEPSS 0.2%CVE-2024-27217MEDIUMMSDP has a use after free vulnerabilityEPSS 0.2%CVE-2026-1289HIGHPDF File Parsing Vulnerabilities in Certain Autodesk Desktop ProductsEPSS 0.2%CVE-2026-33018HIGHlibsixel: Use-After-Free in load_gif()EPSS 0.2%CVE-2026-55406MEDIUMBuffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in DerefEPSS 0.2%CVE-2024-56635HIGHnet: avoid potential UAF in default_operstate()EPSS 0.2%CVE-2023-41093LOWLoss of confidentiality due to potential race condition in Bluetooth controller Connection_Handle reuseEPSS 0.2%CVE-2025-4878LOWLibssh: use of uninitialized variable in privatekey_from_file()EPSS 0.2%CVE-2023-42892HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS EPSS 0.2%CVE-2023-53023HIGHnet: nfc: Fix use-after-free in local_cleanup()EPSS 0.2%CVE-2023-53021HIGHnet/sched: sch_taprio: fix possible use-after-freeEPSS 0.2%CVE-2026-34734HIGHHDF5: H5T__conv_struct Use After FreeEPSS 0.2%CVE-2026-53009HIGHice: fix double-free of tx_buf skbEPSS 0.2%CVE-2026-87628HIGHUse after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside thEPSS 0.2%CVE-2026-12029HIGHUse after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer proceEPSS 0.2%CVE-2021-47669HIGHcan: vxcan: vxcan_xmit: fix use after free bugEPSS 0.2%