Fallos del tipo CWE-416

5143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-22407MEDIUMIn hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to locEPSS 0.1%CVE-2023-48353MEDIUMIn vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution priEPSS 0.1%CVE-2018-9439HIGHIn __unregister_prot_hook and packet_release of af_packet.c, there is a possible use-after-free due to improper locking. This could leadEPSS 0.1%CVE-2025-20787MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20773MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20804MEDIUMIn dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor hEPSS 0.1%CVE-2024-32927HIGHIn sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of pEPSS 0.1%CVE-2025-20802MEDIUMIn geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious aEPSS 0.1%CVE-2025-20806MEDIUMIn dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor hEPSS 0.1%CVE-2025-20770MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20785MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20775MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2024-40669HIGHIn TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additionEPSS 0.1%CVE-2025-20772MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2024-40670HIGHIn TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additionEPSS 0.1%CVE-2022-39847MEDIUMUse after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to peEPSS 0.1%CVE-2025-20805MEDIUMIn dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor hEPSS 0.1%CVE-2024-47017HIGHIn ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead to local escalation oEPSS 0.1%CVE-2025-47339HIGHUse After Free in HLOSEPSS 0.1%CVE-2025-58307MEDIUMUAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%