Fallos del tipo CWE-416

5043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2022-4919HIGHUse after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a craEPSS 0.7%CVE-2022-4916HIGHUse after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform arbitrary read/write via a crafted HTMLEPSS 0.7%CVE-2022-4918HIGHUse after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write via a crafted HTML paEPSS 0.7%CVE-2025-24898MEDIUMrust openssl ssl::select_next_proto use after freeEPSS 0.7%CVE-2024-23322HIGHEnvoy crashes when idle and request per try timeout occur within the backoff intervalEPSS 0.7%CVE-2023-36760HIGH3D Viewer Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-3450HIGHUse after free in Peer Connection in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption EPSS 0.7%CVE-2024-26237HIGHWindows Defender Credential Guard Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2024-43047HIGHUse After Free in DSP ServiceEPSS 0.7%KEVCVE-2023-3389HIGHUse after free in io_uring in the Linux KernelEPSS 0.7%CVE-2023-23421HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2022-4292HIGHUse After Free in vim/vimEPSS 0.7%CVE-2024-7536HIGHUse after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crEPSS 0.7%CVE-2024-30807HIGHAn issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp,EPSS 0.7%CVE-2024-30809HIGHAn issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leaEPSS 0.7%CVE-2025-0240MEDIUMCompartment mismatch when parsing JavaScript JSON moduleEPSS 0.7%CVE-2024-43625HIGHMicrosoft Windows VMSwitch Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2023-48231LOWUse-After-Free in win_close() in vimEPSS 0.7%CVE-2021-3929—A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just likeEPSS 0.7%CVE-2024-50286CRITICALksmbd: fix slab-use-after-free in ksmbd_smb2_session_createEPSS 0.7%