Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2023-6143HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2026-10014HIGHUse after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2026-42958HIGHUse After Free in Labcenter ProteusEPSS 0.2%CVE-2026-23401HIGHKVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTEEPSS 0.2%CVE-2026-40311MEDIUMImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing valuesEPSS 0.2%CVE-2024-4607HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2025-60471MEDIUMA use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 alEPSS 0.2%CVE-2026-39316MEDIUMCUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointerEPSS 0.2%CVE-2026-10012HIGHUse after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.2%CVE-2026-16147MEDIUMit82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruptionEPSS 0.2%CVE-2023-28469MEDIUMAn issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access EPSS 0.2%CVE-2026-47586MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel module where an attacker could cause a use-after-freeEPSS 0.2%CVE-2024-28951MEDIUMArkcompiler runtime has a use after free vulnerabilityEPSS 0.2%CVE-2022-20540HIGHIn SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to locaEPSS 0.2%CVE-2026-31419HIGHnet: bonding: fix use-after-free in bond_xmit_broadcast()EPSS 0.2%CVE-2026-28529HIGHcryptodev-linux <= 1.14 get_userbuf Use After Free LPEEPSS 0.2%CVE-2022-20571MEDIUMIn extract_metadata of dm-android-verity.c, there is a possible way to corrupt kernel memory due to a use after free. This could lead to locEPSS 0.2%CVE-2022-20514MEDIUMIn acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possiEPSS 0.2%CVE-2026-71226HIGHLibkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio pathEPSS 0.2%CVE-2022-20554MEDIUMIn removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of priEPSS 0.2%