Fallos del tipo CWE-416

5142 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-84567MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. AnEPSS 0.2%CVE-2026-21486HIGHUse After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write in iccDEVEPSS 0.2%CVE-2026-19108MEDIUMMZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after freeEPSS 0.2%CVE-2026-12445HIGHUse after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extensEPSS 0.2%CVE-2026-65377MEDIUMA memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27EPSS 0.2%CVE-2026-17891MEDIUMUse after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer procesEPSS 0.2%CVE-2026-84552MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden GEPSS 0.2%CVE-2025-39863HIGHwifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info workEPSS 0.2%CVE-2024-41160HIGHLiteos-A has an use after free vulnerabilityEPSS 0.2%CVE-2024-1067HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2023-53263HIGHdrm/nouveau/disp: fix use-after-free in error handling of nouveau_connector_createEPSS 0.2%CVE-2026-77235HIGHMissing privilege check in SecureContext_FreeContext in FreeRTOS-KernelEPSS 0.2%CVE-2024-10074HIGHLiteos_a has an use after free vulnerabilityEPSS 0.2%CVE-2025-23098HIGHAn issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor EPSS 0.2%CVE-2022-50421HIGHrpmsg: char: Avoid double destroy of default endpointEPSS 0.2%CVE-2024-23354HIGHUse After Free in Graphics LinuxEPSS 0.2%CVE-2026-14048MEDIUMUse after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially EPSS 0.2%CVE-2026-73071LOWVim: Use-after-free in JSON DecodingEPSS 0.2%CVE-2026-13879MEDIUMUse after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sEPSS 0.2%CVE-2023-5447MEDIUMUse-After-Free in Service for Hardware Support App for Fingerprint DriverEPSS 0.2%