Fallos del tipo CWE-416

5143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-11072HIGHUse after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a maliciEPSS 0.1%CVE-2025-21453HIGHUse After Free in GPS HLOS DriverEPSS 0.1%CVE-2025-21437HIGHUse After Free in Automotive Linux OSEPSS 0.1%CVE-2026-76957MEDIUMlibexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is simiEPSS 0.1%CVE-2025-21436HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2022-36855MEDIUMA use after free vulnerability in iva_ctl driver prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.EPSS 0.1%CVE-2022-20372HIGHIn exynos5_i2c_irq of (TBD), there is a possible out of bounds write due to a use after free. This could lead to local escalation of privileEPSS 0.1%CVE-2026-24917MEDIUMUAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-20414MEDIUMIn imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a maliciouEPSS 0.1%CVE-2025-27723MEDIUMUse after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Kernel may allow a denEPSS 0.1%CVE-2024-23697HIGHIn RGXCreateHWRTData_aux of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalaEPSS 0.1%CVE-2024-33034HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2024-23696HIGHIn RGXCreateZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalatiEPSS 0.1%CVE-2026-7925HIGHUse after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalEPSS 0.1%CVE-2024-45571HIGHUse After Free in WLAN Host CommunicationEPSS 0.1%CVE-2026-58751MEDIUMIn multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalaEPSS 0.1%CVE-2024-38424HIGHUse After Free in GPSEPSS 0.1%CVE-2025-47359HIGHUse After Free in Secure ProcessorEPSS 0.1%CVE-2024-38419HIGHUse After Free in Automotive GPUEPSS 0.1%CVE-2025-47358HIGHUse After Free in Secure ProcessorEPSS 0.1%