Fallos del tipo CWE-416

5143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2024-38419HIGHUse After Free in Automotive GPUEPSS 0.1%CVE-2024-38424HIGHUse After Free in GPSEPSS 0.1%CVE-2025-47358HIGHUse After Free in Secure ProcessorEPSS 0.1%CVE-2024-33055MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2024-33053MEDIUMUse After Free in VideoEPSS 0.1%CVE-2023-43544MEDIUMUse After Free in AudioEPSS 0.1%CVE-2024-33029MEDIUMUse After Free in DSP ServicesEPSS 0.1%CVE-2026-20411HIGHIn cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious aEPSS 0.1%CVE-2024-33033MEDIUMUse After Free in ComputerVisionEPSS 0.1%CVE-2024-38411MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2017-18153MEDIUMUse After Free in WLANEPSS 0.1%CVE-2025-48521MEDIUMImproper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) conditEPSS 0.1%CVE-2025-22404HIGHIn avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local EPSS 0.1%CVE-2025-22405HIGHIn multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of priEPSS 0.1%CVE-2025-22406HIGHIn bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to lEPSS 0.1%CVE-2025-22410HIGHIn multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of priEPSS 0.1%CVE-2025-27063HIGHUse After Free in VideoEPSS 0.1%CVE-2025-47322HIGHUse After Free in Automotive Linux OSEPSS 0.1%CVE-2026-34854MEDIUMUAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.EPSS 0.1%CVE-2025-36934HIGHIn bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could EPSS 0.1%