Falhas do tipo CWE-416

5.043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-50153HIGHDesktop Window Manager Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2021-20226—A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of servicEPSS 0.4%CVE-2026-74937HIGHUse-after-free in the JavaScript: GC componentEPSS 0.4%CVE-2026-84123HIGHPrivilege escalation due to use-after-free in the Graphics: WebGPU componentEPSS 0.4%CVE-2024-34117HIGHAdobe Photoshop 2024 MPO File Parsing Use-After-Free vulnerabilityEPSS 0.4%CVE-2024-23142HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2023-38216MEDIUMZDI-CAN-21404: Adobe Bridge Font Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-21551HIGHMicrosoft Cryptographic Services Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-4725CRITICALSandbox escape due to use-after-free in the Graphics: Canvas2D componentEPSS 0.4%CVE-2026-21251HIGHCluster Client Failover (CCF) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-42364MEDIUMA use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evalEPSS 0.4%CVE-2025-0151HIGHZoom Apps - Use After FreeEPSS 0.4%CVE-2022-1198—A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by siEPSS 0.4%CVE-2023-42108HIGHPDF-XChange Editor EMF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-37355LOWKofax Power PDF JPG File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2018-14619MEDIUMA flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when eachEPSS 0.4%CVE-2026-53071HIGHBluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rspEPSS 0.4%CVE-2026-64783HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS TaEPSS 0.4%CVE-2023-21756HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-71847HIGHRuby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streamsEPSS 0.4%