Fallos del tipo CWE-416

5043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2023-36804HIGHWindows GDI Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-10459MEDIUMAn attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerabilitEPSS 0.6%CVE-2025-54908HIGHMicrosoft PowerPoint Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-2766CRITICALUse-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-2767HIGHUse-after-free in the JavaScript: WebAssembly componentEPSS 0.6%CVE-2026-2765CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2026-2758CRITICALUse-after-free in the JavaScript: GC componentEPSS 0.6%CVE-2026-32942HIGHPJSIP has ICE session use-after-free race conditionsEPSS 0.6%CVE-2026-2772HIGHUse-after-free in the Audio/Video: Playback componentEPSS 0.6%CVE-2026-2764CRITICALJIT miscompilation, use-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-2763CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2026-2770HIGHUse-after-free in the DOM: Bindings (WebIDL) componentEPSS 0.6%CVE-2025-14321CRITICALUse-after-free in the WebRTC: Signaling componentEPSS 0.6%CVE-2025-58718HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-2769HIGHUse-after-free in the Storage: IndexedDB componentEPSS 0.6%CVE-2024-7000HIGHUse after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gesturEPSS 0.6%CVE-2026-74944CRITICALUse-after-free in the DOM: Core & HTML componentEPSS 0.6%CVE-2026-67300HIGHFreeRDP before 3.29.0 Use-After-Free via async message proxyEPSS 0.6%CVE-2024-4770HIGHWhen saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126,EPSS 0.6%CVE-2026-74936CRITICALUse-after-free in the JavaScript: WebAssembly componentEPSS 0.6%