Fallos del tipo CWE-416

5143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2023-21020MEDIUMIn registerSignalHandlers of main.c, there is a possible local arbitrary code execution due to a use after free. This could lead to local esEPSS 0.1%CVE-2023-20744MEDIUMIn vcu, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privEPSS 0.1%CVE-2023-21043MEDIUMIn (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with EPSS 0.1%CVE-2023-21042MEDIUMIn (TBD) of (TBD), there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with EPSS 0.1%CVE-2023-40114HIGHIn multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalaEPSS 0.1%CVE-2026-58093HIGHKernel use-after-free via tty ioctlsEPSS 0.1%CVE-2025-58299HIGHUse After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-20707MEDIUMIn geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious aEPSS 0.1%CVE-2023-21018MEDIUMIn UnwindingWorker of unwinding.cc, there is a possible out of bounds write due to a use after free. This could lead to local escalation of EPSS 0.1%CVE-2023-21038MEDIUMIn cs40l2x_cp_trigger_queue_show of cs40l2x.c, there is a possible out of bounds write due to a use after free. This could lead to local escEPSS 0.1%CVE-2025-27031HIGHUse After Free in Bluetooth HOSTEPSS 0.1%CVE-2025-20706HIGHIn mbrain, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actoEPSS 0.1%CVE-2022-36849MEDIUMUse after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to peEPSS 0.1%CVE-2025-20705HIGHIn monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a maliciouEPSS 0.1%CVE-2023-21045MEDIUMWhen cpif handles probe failures, there is a possible out of bounds read due to a use after free. This could lead to local information disclEPSS 0.1%CVE-2022-36847MEDIUMUse after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform maliciousEPSS 0.1%CVE-2025-53185MEDIUMVirtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory ImpactEPSS 0.1%CVE-2025-27047HIGHUse After Free in DisplayEPSS 0.1%CVE-2025-27056HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2025-27050HIGHUse After Free in CameraEPSS 0.1%