Fallos del tipo CWE-416

5072 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2024-8362HIGHUse after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.6%CVE-2024-30304HIGHZDI-CAN-23040: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.6%CVE-2022-3134HIGHUse After Free in vim/vimEPSS 0.6%CVE-2023-36902HIGHWindows Runtime Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-42970HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS EPSS 0.6%CVE-2025-24078HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-53735HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-50154CRITICALtcp/dccp: Don't use timer_pending() in reqsk_queue_unlink().EPSS 0.6%CVE-2022-33981LOWdrivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free flaw EPSS 0.6%CVE-2023-42089LOWFoxit PDF Reader templates Use-After-Free Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-61861MEDIUMImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaptionEPSS 0.6%CVE-2022-26385MEDIUMIn unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free cauEPSS 0.6%CVE-2024-38924CRITICALOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl proceEPSS 0.6%CVE-2026-26448CRITICALStomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently anEPSS 0.6%CVE-2024-38923CRITICALOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl proceEPSS 0.6%CVE-2024-53177CRITICALsmb: prevent use-after-free due to open_cached_dir error pathsEPSS 0.6%CVE-2026-82631LOWvalkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after freeEPSS 0.6%CVE-2026-34774HIGHElectron: Use-after-free in offscreen child window paint callbackEPSS 0.6%CVE-2024-10826HIGHUse after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heEPSS 0.6%CVE-2023-27338LOWPDF-XChange Editor TIF File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.6%