Fallos del tipo CWE-416

5143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2025-58311MEDIUMUAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentialiEPSS 0.1%CVE-2025-20743MEDIUMIn clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a maliciouEPSS 0.1%CVE-2026-56914HIGHIn multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no EPSS 0.1%CVE-2025-20799HIGHIn c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor EPSS 0.1%CVE-2026-20443MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20744MEDIUMIn pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious aEPSS 0.1%CVE-2018-9417HIGHIn f_hidg_read and hidg_disable of f_hid.c, there is a possible use-after-free due to improper locking. This could lead to local escalation EPSS 0.1%CVE-2026-11115HIGHUse after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2025-36922MEDIUMIn bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to local escalation of priEPSS 0.1%CVE-2024-29787HIGHIn lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due to a use after free. This could lead to EPSS 0.1%CVE-2025-47333MEDIUMUse After Free in HLOSEPSS 0.1%CVE-2025-20745MEDIUMIn apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actoEPSS 0.1%CVE-2026-24082HIGHUse After Free in Automotive GPUEPSS 0.1%CVE-2024-23716HIGHIn DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead to local escalation EPSS 0.1%CVE-2026-21380HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2024-47033HIGHIn lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after free. This could lead to local escalatiEPSS 0.1%CVE-2018-9344HIGHIn several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalationEPSS 0.1%CVE-2025-47381HIGHUse After Free in Automotive AudioEPSS 0.1%CVE-2025-47376HIGHUse After Free in Automotive AudioEPSS 0.1%CVE-2025-47386HIGHUse After Free in Automotive AudioEPSS 0.1%