Falhas do tipo CWE-416

5.043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-10982HIGHUse after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a cEPSS 0.5%CVE-2023-42050LOWPDF-XChange Editor EMF File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-8953CRITICALSandbox escape due to use-after-free in the Disability Access APIs componentEPSS 0.5%CVE-2026-10975HIGHUse after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.5%CVE-2026-10939HIGHUse after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.5%CVE-2020-1712HIGHA heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handEPSS 0.5%CVE-2026-11003HIGHUse after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.5%CVE-2025-12105HIGHLibsoup: heap use-after-free in libsoup message queue handling during http/2 read completionEPSS 0.5%CVE-2022-35704HIGHAdobe Bridge SVG File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-22071HIGHPossible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon AEPSS 0.5%KEVCVE-2026-14121CRITICALUse after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via maliciEPSS 0.5%CVE-2026-65338MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and EPSS 0.5%CVE-2022-35675HIGHAdobe FrameMaker SVG File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-1079MEDIUMA flaw was found in the Linux kernel. A use-after-free may be triggered in asus_kbd_backlight_set when plugging/disconnecting in a maliciousEPSS 0.5%CVE-2026-12706MEDIUMFfmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()EPSS 0.5%CVE-2023-3609HIGHUse-after-free in Linux kernel's net/sched: cls_u32 componentEPSS 0.5%CVE-2026-2786HIGHUse-after-free in the JavaScript Engine componentEPSS 0.5%CVE-2025-59243HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2020-14373—A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDFEPSS 0.5%CVE-2024-30161MEDIUMIn Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier andEPSS 0.5%