Fallos del tipo CWE-416

5143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2024-38399HIGHUse After Free in GraphicsEPSS 0.1%CVE-2024-40885HIGHUse after free in the UEFI firmware of some Intel(R) Server M20NTP BIOS may allow a privileged user to potentially enable escalation of privEPSS 0.1%CVE-2025-55308MEDIUMAn issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calEPSS 0.1%CVE-2023-22383MEDIUMUse After Free in CameraEPSS 0.1%CVE-2026-87533HIGHUse after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox viEPSS 0.1%CVE-2026-63380MEDIUMLibevent: Null Pointer Dereference in `evws_new_session`EPSS 0.1%CVE-2026-13778HIGHUse after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious pEPSS 0.1%CVE-2023-22668MEDIUMUse After Free in AudioEPSS 0.1%CVE-2026-17716HIGHUse after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via maliciEPSS 0.1%CVE-2022-32607MEDIUMIn aee, there is a possible use after free due to a missing bounds check. This could lead to local escalation of privilege with System execuEPSS 0.1%CVE-2025-25177MEDIUMGPU DDK - Roll-back of pvr_exp_fence not in finalised state can cause UAFEPSS 0.1%CVE-2024-47892HIGHGPU DDK - UAF of kernel memory in PMRUnlockPhysAddressesOSMem for on-demand non-4KB PMRs in system memory (UMA)EPSS 0.1%CVE-2024-46971HIGHGPU DDK - UAF of memory in PMRUnlockSysPhysAddressesLocalMem for on-demand PMRs on PCI (LMA) systemsEPSS 0.1%CVE-2026-17862HIGHUse after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2026-95315HIGHUse after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the saEPSS 0.1%CVE-2026-17699HIGHUse after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicEPSS 0.1%CVE-2025-55309MEDIUMAn issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScriEPSS 0.1%CVE-2026-15905HIGHUse after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a maliciEPSS 0.1%CVE-2026-14018HIGHUse after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2026-26071MEDIUMEVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Use‑After‑FreeEPSS 0.1%