Fallos del tipo CWE-416

5043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2024-30333HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30331HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30332HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30322HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-24990HIGHNGINX HTTP/3 QUIC vulnerabilityEPSS 0.9%CVE-2024-30324HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30334HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-67385HIGHMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-57092CRITICALMicrosoft Windows VMSwitch Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-69551HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-58626HIGHWindows Remote Desktop Services Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-69712HIGHWindows Key Distribution Center Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-50666HIGHWindows Remote Access Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-62818HIGHWindows Active Directory Certificate Services (AD CS) Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-23669HIGHRPC Runtime Library Remote Code Execution VulnerabilityEPSS 0.9%CVE-2022-26710HIGHA use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, EPSS 0.9%CVE-2022-26709HIGHA use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.EPSS 0.9%CVE-2022-2738—The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman EPSS 0.9%CVE-2022-3534MEDIUMLinux Kernel libbpf btf_dump.c btf_dump_name_dups use after freeEPSS 0.9%CVE-2026-25997MEDIUMFreeRDP has heap-use-after-free in xf_clipboard_format_equalEPSS 0.9%