Fallos del tipo CWE-416

5043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2024-30102HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.8%CVE-2022-37374HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.8%CVE-2018-10876MEDIUMA flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() function when mountingEPSS 0.8%CVE-2025-43222CRITICALA use-after-free issue was addressed by removing the vulnerable code. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS SonomaEPSS 0.8%CVE-2023-0699HIGHUse after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a craftedEPSS 0.8%CVE-2024-5494HIGHUse after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a craftEPSS 0.8%CVE-2022-48666CRITICALscsi: core: Fix a use-after-freeEPSS 0.8%CVE-2022-3198HIGHUse after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafteEPSS 0.8%CVE-2023-38669HIGHUse after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition. EPSS 0.8%CVE-2023-1528HIGHUse after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to pEPSS 0.8%CVE-2024-49021HIGHMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 0.8%CVE-2022-3886HIGHUse after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruptiEPSS 0.8%CVE-2024-49027HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.8%CVE-2021-32495CRITICALRadare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will alEPSS 0.8%CVE-2026-34332HIGHWindows Kernel-Mode Driver Remote Code Execution VulnerabilityEPSS 0.8%CVE-2025-43368MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26EPSS 0.8%CVE-2025-29820HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-27950MEDIUMFreeRDP heap-use-after-free in update_pointer_new(SDL): Fix Applied in the Wrong FileEPSS 0.8%CVE-2023-21822HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2023-2461HIGHUse after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in sEPSS 0.8%