Fallos del tipo CWE-416

5075 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2026-42900HIGHMicrosoft Windows App Store Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-50460HIGHWindows Runtime Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-69827HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-69782HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-2912MEDIUMSiteManager Embedded service disruptionEPSS 0.5%CVE-2026-62778HIGHWindows DNS Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-1218HIGHUse after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.5%CVE-2023-51563HIGHKofax Power PDF XPS File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-52997HIGHPhotoshop Desktop | Use After Free (CWE-416)EPSS 0.5%CVE-2024-53953HIGHAnimate | Use After Free (CWE-416)EPSS 0.5%CVE-2023-51565HIGHKofax Power PDF XPS File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-1216HIGHUse after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in directEPSS 0.5%CVE-2026-8092HIGHMemory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2EPSS 0.5%CVE-2026-94084CRITICALSuricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with EPSS 0.5%CVE-2026-90852MEDIUMluben zstd-jni Dictionary Sharing ZstdCompressCtx.java ZstdCompressCtx.loadDict use after freeEPSS 0.5%CVE-2023-53338CRITICALlwt: Fix return values of BPF xmit opsEPSS 0.5%CVE-2023-38111HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-38117HIGHFoxit PDF Reader AcroForm Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-38112HIGHFoxit PDF Reader XFA Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-38107HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%