Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-24301LOWArkcompiler Ets Runtime has an UAF vulnerabilityEPSS 0.2%CVE-2025-20091LOWCommunication Dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2026-7349HIGHUse after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code iEPSS 0.2%CVE-2026-57589HIGHsys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-afEPSS 0.2%CVE-2026-0001MEDIUMMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2025-43478MEDIUMA use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOEPSS 0.2%CVE-2025-20626LOWArkcompiler Ets Runtime has an UAF vulnerabilityEPSS 0.2%CVE-2026-11656HIGHUse after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extEPSS 0.2%CVE-2025-23409LOWCommunication Dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2023-6363MEDIUMMali GPU Kernel Driver allows improper GPU processing operationsEPSS 0.2%CVE-2025-23414LOWArkcompiler Ets Runtime has an UAF vulnerabilityEPSS 0.2%CVE-2026-6040MEDIUMHeap use-after-free in ODF number-format blank-width parsingEPSS 0.2%CVE-2026-49422HIGHUse-after-free in TCP RACK stack option handlerEPSS 0.2%CVE-2025-61864HIGHA use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lEPSS 0.2%CVE-2026-92472MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2026-92474MEDIUMGPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after freeEPSS 0.2%CVE-2026-43684HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27,EPSS 0.2%CVE-2024-39831MEDIUMAccessTokenManager has an use after free vulnerabilityEPSS 0.2%CVE-2026-90578MEDIUMGPAC MP4Box list.c gf_list_count use after freeEPSS 0.2%CVE-2026-58083HIGHUse-after-free in kqueue copy-on-forkEPSS 0.2%