Fallos del tipo CWE-416

5143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2024-23383HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2023-33120HIGHUse After Free in AudioEPSS 0.1%CVE-2024-23376MEDIUMUse After Free in ComputerVisionEPSS 0.1%CVE-2024-45540MEDIUMUse After Free in HLOSEPSS 0.1%CVE-2018-11816HIGHUse After Free in VideoEPSS 0.1%CVE-2023-33117HIGHUse After Free in AudioEPSS 0.1%CVE-2023-33118HIGHUse After Free in Automotive AudioEPSS 0.1%CVE-2024-45544MEDIUMUse After Free in Data Network Stack & ConnectivityEPSS 0.1%CVE-2024-23370MEDIUMUse After Free in Automotive MultimediaEPSS 0.1%CVE-2023-43521MEDIUMUse After Free in HLOSEPSS 0.1%CVE-2026-14094HIGHUse after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalaEPSS 0.1%CVE-2026-11891MEDIUMMali GPU Userspace Driver allows access to already freed memoryEPSS 0.1%CVE-2026-12387MEDIUMMali GPU Kernel Driver allows access to already freed memoryEPSS 0.1%CVE-2026-13844HIGHUse after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2026-12449HIGHUse after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escaEPSS 0.1%CVE-2026-13827HIGHUse after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a maliEPSS 0.1%CVE-2024-45554HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2026-34859MEDIUMUAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.EPSS 0.1%CVE-2025-47398HIGHUse After Free in GraphicsEPSS 0.1%CVE-2023-20849MEDIUMIn imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege wEPSS 0.1%