Fallos del tipo CWE-416

5043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2021-0270HIGHJunos OS: PTX Series, QFX10K Series: A PTX/QFX FPC may restart unexpectedly with the "inline-Jflow" feature enabled on a large-scale deploymentEPSS 0.7%CVE-2023-6241HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.7%CVE-2022-3304HIGHUse after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a craftedEPSS 0.7%CVE-2023-21774HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2024-8384CRITICALThe JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two paEPSS 0.7%CVE-2023-32018HIGHWindows Hello Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-29365HIGHWindows Media Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-23514HIGHA use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS EPSS 0.7%CVE-2026-21235HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-0794HIGHALGO 8180 IP Audio Alerter SIP Use-After-Free Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-1196MEDIUMAfter a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable EPSS 0.7%CVE-2024-38235MEDIUMWindows Hyper-V Denial of Service VulnerabilityEPSS 0.7%CVE-2023-25735HIGHCross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment EPSS 0.7%CVE-2026-73513HIGHEnvoy: oghttp2 upstream trailers incorrect handlingEPSS 0.7%CVE-2024-43556HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2025-23115CRITICALA Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor with access to UniFi EPSS 0.7%CVE-2023-5380MEDIUMXorg-x11-server: use-after-free bug in destroywindowEPSS 0.7%CVE-2024-30049HIGHWindows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2021-33796CRITICALIn MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service. EPSS 0.7%CVE-2024-30329LOWFoxit PDF Reader Annotation Use-After-Free Information Disclosure VulnerabilityEPSS 0.7%