Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-49496MEDIUMGhidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector ReallocationEPSS 0.2%CVE-2026-63729MEDIUMTeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX FileEPSS 0.2%CVE-2026-5398HIGHKernel use-after-free bug in the TIOCNOTTY handlerEPSS 0.2%CVE-2026-12451HIGHUse after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2026-56131MEDIUMlibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. TEPSS 0.2%CVE-2026-2889MEDIUMCCExtractor mp4.c processmp4 use after freeEPSS 0.2%CVE-2026-3777MEDIUMUse after free of view cache in Foxit PDF Editor/ReaderEPSS 0.2%CVE-2026-12014HIGHUse after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a saEPSS 0.2%CVE-2022-29919HIGHUse after free in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of pEPSS 0.2%CVE-2026-57256HIGHFoxit Editor/Reader List Box Format Use-After-Free VulnerabilityEPSS 0.2%CVE-2026-84506HIGHA use after free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOSEPSS 0.2%CVE-2026-10001HIGHUse after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2021-37652HIGHUse after free in boosted trees creation in TensorFlowEPSS 0.2%CVE-2024-32502HIGHAn issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, EEPSS 0.2%CVE-2023-46708MEDIUMWlan has a use after free vulnerabilityEPSS 0.2%CVE-2023-28980MEDIUMJunos OS and Junos OS Evolved: In a BGP rib sharding scenario an rpd crash will happen shortly after a specific CLI command is issuedEPSS 0.2%CVE-2025-0427HIGHMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2026-65407MEDIUMA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 2EPSS 0.2%CVE-2023-20933HIGHIn several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalatiEPSS 0.2%CVE-2025-52885MEDIUMGHSL-2025-042: Poppler has Use-After-FreeEPSS 0.2%