Fallos del tipo CWE-416

5143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-14018HIGHUse after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2025-5991LOWUse after free in QHttp2ProtocolHandlerEPSS 0.1%CVE-2026-71968HIGHOP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENTEPSS 0.1%CVE-2026-91791HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.1%CVE-2025-14569MEDIUMggml-org whisper.cpp common-whisper.cpp read_audio_data use after freeEPSS 0.1%CVE-2023-20920HIGHIn queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of priviEPSS 0.1%CVE-2026-4752MEDIUMUse After Free in No-Chicken Echo-MateEPSS 0.1%CVE-2022-22077HIGHMemory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon MobileEPSS 0.1%CVE-2026-17932MEDIUMUse after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive iEPSS 0.1%CVE-2026-57842HIGHNetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlenEPSS 0.1%CVE-2026-56117MEDIUMdhcpcd Heap Use-After-Free via Control Socket HandlingEPSS 0.1%CVE-2026-91799HIGHFoxit Editor/Reader Array resetForm Use-After-Free VulnerabilityEPSS 0.1%CVE-2026-87514HIGHUse after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via aEPSS 0.1%CVE-2026-13713MEDIUMYAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stackEPSS 0.1%CVE-2026-47516HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successfEPSS 0.1%CVE-2026-79245HIGHUse after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer process to execute arEPSS 0.1%CVE-2026-47551HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause a use-after-free.EPSS 0.1%CVE-2026-47560HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a use-after-freEPSS 0.1%CVE-2024-45553HIGHUse After Free in DSP ServicesEPSS 0.1%CVE-2024-33059MEDIUMUse After Free in Computer VisionEPSS 0.1%