Fallos del tipo CWE-416

5142 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-58090HIGHUse-after-free in unix SOCK_STREAM message handlingEPSS 0.2%CVE-2023-53388HIGHdrm/mediatek: Clean dangling pointer on bind error pathEPSS 0.2%CVE-2024-56556HIGHbinder: fix node UAF in binder_add_freeze_work()EPSS 0.2%CVE-2025-0819HIGHMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2026-84593MEDIUMA use after free issue was addressed with improved memory management. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to cauEPSS 0.2%CVE-2025-39861HIGHBluetooth: vhci: Prevent use-after-free by removing debugfs files earlyEPSS 0.2%CVE-2026-49412HIGHUse-after-free bug in the IPV6_MSFILTER socket option handlerEPSS 0.2%CVE-2024-22180LOWCamera has a use after free vulnerabilityEPSS 0.2%CVE-2026-0465MEDIUMA Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentialEPSS 0.2%CVE-2025-13350HIGHUse-after-free of orphaned AF_UNIX in Ubuntu builds of Linux kernelEPSS 0.2%CVE-2025-20081LOWCommunication Dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2025-39882HIGHdrm/mediatek: fix potential OF node use-after-freeEPSS 0.2%CVE-2025-0073HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2026-87633HIGHUse after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UEPSS 0.2%CVE-2023-49142MEDIUMmultimedia audio has a UAF vulnerabilityEPSS 0.2%CVE-2023-5249HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2023-53426HIGHxsk: Fix xsk_diag use-after-free error during socket cleanupEPSS 0.2%CVE-2025-39854HIGHice: fix NULL access of tx->in_use in ice_ll_ts_intrEPSS 0.2%CVE-2026-13282MEDIUMUse after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruptiEPSS 0.2%CVE-2026-26203MEDIUMPJSIP's pjmedia-video has use-after-free in H264 packetizer when packetizing fragmented NALEPSS 0.1%