Fallos del tipo CWE-416

5143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2022-39853MEDIUMA use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to cause memory access fault.EPSS 0.1%CVE-2022-25666MEDIUMMemory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon Compute, EPSS 0.1%CVE-2026-34983LOWWasmtime has a use-after-free bug after cloning `wasmtime::Linker`EPSS 0.1%CVE-2026-100503MEDIUMGhidra through 12.1.4 Heap Use-After-Free in DecompilerEPSS 0.1%CVE-2026-21102CRITICALUse after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.EPSS 0.1%CVE-2024-27213HIGHIn BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escEPSS 0.1%CVE-2024-43057HIGHUse After Free in MProcEPSS 0.1%CVE-2024-45580HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2024-43062HIGHUse After Free in Camera LinuxEPSS 0.1%CVE-2024-23382HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2026-97222MEDIUMGnumeric: gnumeric: heap use-after-free when opening a malformed workbookEPSS 0.1%CVE-2024-43061HIGHUse After Free in AudioEPSS 0.1%CVE-2025-21424HIGHUse After Free in NPUEPSS 0.1%CVE-2024-43059HIGHUse After Free in Automotive MultimediaEPSS 0.1%CVE-2024-53023HIGHUse After Free in Automotive Android OSEPSS 0.1%CVE-2026-47597HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileEPSS 0.1%CVE-2022-33292HIGHUse after free in Qualcomm IPCEPSS 0.1%CVE-2023-33029HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2023-33021HIGHUse After Free in GraphicsEPSS 0.1%CVE-2026-91816HIGHFoxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.1%