Fallos del tipo CWE-416

5142 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-14366MEDIUMSiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pktEPSS 0.2%CVE-2025-6636HIGHPRT File Parsing Use-After-Free VulnerabilityEPSS 0.2%CVE-2026-49743HIGHGPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closedEPSS 0.2%CVE-2025-39855HIGHice: fix NULL access of tx->in_use in ice_ptp_ts_irqEPSS 0.2%CVE-2026-7477HIGHMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2025-60466MEDIUMA use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackersEPSS 0.2%CVE-2026-5729HIGHMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2026-45200HIGHGPU DDK - Double free in _FreeOSPages due to incorrect allocation flag set by _EncodeAllocationFlagsEPSS 0.2%CVE-2026-41158HIGHGPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrinkEPSS 0.2%CVE-2025-23281HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race conditioEPSS 0.2%CVE-2026-7476HIGHMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2026-41156HIGHGPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding referenceEPSS 0.2%CVE-2026-9034HIGHMali GPU Userspace Driver allows access to already freed memoryEPSS 0.2%CVE-2026-5939MEDIUMUAF in Foxit PDF Editor/Reader via XFA calculate eventEPSS 0.2%CVE-2026-34192HIGHGPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entriesEPSS 0.2%CVE-2025-6973HIGHUse After Free vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2023-53373HIGHcrypto: seqiv - Handle EBUSY correctlyEPSS 0.2%CVE-2025-6972HIGHUse After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2025-64468HIGHUse-after-Free in sentry!sentry_span_set_data() in NI LabVIEWEPSS 0.2%CVE-2026-15194MEDIUMOpen5GS AMF context.c amf_context_final use after freeEPSS 0.2%