Fallos del tipo CWE-416

5043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2024-4770HIGHWhen saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126,EPSS 0.6%CVE-2024-7964HIGHUse after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruptEPSS 0.6%CVE-2023-36008MEDIUMMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-40215MEDIUMA race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash orEPSS 0.6%CVE-2023-38161HIGHWindows GDI Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2020-25670—A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalEPSS 0.6%CVE-2023-0929HIGHUse after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a craEPSS 0.6%CVE-2024-34362MEDIUMEnvoy affected by a crash (use-after-free) in EnvoyQuicServerStreamEPSS 0.6%CVE-2026-28928CRITICALA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOEPSS 0.6%CVE-2023-4206HIGHUse-after-free in Linux kernel's net/sched: cls_route componentEPSS 0.6%CVE-2026-64751CRITICALA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOEPSS 0.6%CVE-2026-64729CRITICALA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOEPSS 0.6%CVE-2026-43814CRITICALA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOEPSS 0.6%CVE-2025-21345HIGHMicrosoft Office Visio Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-20953HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-38927CRITICALOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl proceEPSS 0.6%CVE-2024-38926CRITICALOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl proceEPSS 0.6%CVE-2024-38925CRITICALOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl proceEPSS 0.6%CVE-2026-18924CRITICALHTTP/2 server push UAFEPSS 0.6%CVE-2025-24044HIGHWindows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityEPSS 0.6%