Fallos del tipo CWE-416

5043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-25997MEDIUMFreeRDP has heap-use-after-free in xf_clipboard_format_equalEPSS 0.9%CVE-2022-2862HIGHUse After Free in vim/vimEPSS 0.9%CVE-2024-30330HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-0494HIGHA vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSeEPSS 0.9%CVE-2024-5496HIGHUse after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandboEPSS 0.9%CVE-2024-30327HIGHFoxit PDF Reader template Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2025-48593HIGHIn bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remEPSS 0.9%CVE-2023-7152MEDIUMMicroPython modselect.c poll_set_add_fd use after freeEPSS 0.9%CVE-2023-28081CRITICALA bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and EPSS 0.9%CVE-2025-21756HIGHvsock: Keep the binding until socket destructionEPSS 0.9%CVE-2024-27308HIGHMio's tokens for named pipes may be delivered after deregistrationEPSS 0.9%CVE-2024-1060HIGHUse after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a craEPSS 0.9%CVE-2026-56684HIGHValkey: TLS pending-data processing use-after-free may allow remote code executionEPSS 0.9%CVE-2023-35942MEDIUMEnvoy's gRPC access log crash caused by the listener drainingEPSS 0.9%CVE-2024-2627HIGHUse after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.9%CVE-2024-9254HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-21795HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2020-36773CRITICALArtifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a singleEPSS 0.9%CVE-2021-43825MEDIUMUse-after-free in EnvoyEPSS 0.9%CVE-2023-1818HIGHUse after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.9%