Falhas do tipo CWE-416

5.043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-42040HIGHPDF-XChange Editor mailForm Use-After-Free Code Execution VulnerabilityEPSS 0.5%CVE-2023-42059HIGHPDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-53185HIGHsmb: client: fix NULL ptr deref in crypto_aead_setkey()EPSS 0.5%CVE-2024-0807HIGHUse after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.5%CVE-2023-42086HIGHPDF-XChange Editor EMF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-81934HIGHRedis TLS pending-data list use-after-freeEPSS 0.5%CVE-2024-36013HIGHBluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()EPSS 0.5%CVE-2026-68886MEDIUMWindows Network Connection Broker Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-32712HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-38428MEDIUMAdobe Photoshop DCM File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-58735HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-23135HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.5%CVE-2025-58732HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-34263HIGHAdobe Illustrator Font Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-8637HIGHUse after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corEPSS 0.5%CVE-2026-74969HIGHUse-after-free in the Layout: Text and Fonts componentEPSS 0.5%CVE-2024-50086CRITICALksmbd: fix user-after-free from session log offEPSS 0.5%CVE-2024-6774HIGHUse after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specifEPSS 0.5%CVE-2022-3314MEDIUMUse after free in logging in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentialEPSS 0.5%CVE-2026-43632CRITICALllama.cpp b7492–b9060 Use-After-Free in Tokenization EndpointsEPSS 0.5%